Fortinet FortiPortal 7.2.1

CPE Details

Fortinet FortiPortal 7.2.1
7.2.1
2024-01-17
13h40 +00:00
2024-01-17
13h40 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fortinet:fortiportal:7.2.1:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortiportal

Version

7.2.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-35278 2025-01-14 14h09 +00:00 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
4.3
Medium
CVE-2024-23105 2024-05-14 16h19 +00:00 A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
7.5
High
CVE-2023-48783 2024-01-10 17h51 +00:00 An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
5.4
Medium
CVE-2023-46712 2024-01-10 17h51 +00:00 A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
8.8
High