Fortinet FortiPortal 7.0.0

CPE Details

Fortinet FortiPortal 7.0.0
7.0.0
2023-02-23
14h08 +00:00
2023-02-23
14h10 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fortinet:fortiportal:7.0.0:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortiportal

Version

7.0.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-35278 2025-01-14 14h09 +00:00 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
4.3
Medium
CVE-2023-47543 2024-11-12 18h53 +00:00 An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.
8.1
High
CVE-2024-21759 2024-07-09 15h33 +00:00 An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
4.3
Medium
CVE-2024-31495 2024-06-11 14h31 +00:00 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.
4.3
Medium
CVE-2024-23105 2024-05-14 16h19 +00:00 A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
7.5
High
CVE-2024-21761 2024-03-12 15h09 +00:00 An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
4.3
Medium
CVE-2023-48783 2024-01-10 17h51 +00:00 An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
5.4
Medium
CVE-2023-46712 2024-01-10 17h51 +00:00 A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
8.8
High
CVE-2023-48791 2023-12-13 06h45 +00:00 An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.
8.8
High
CVE-2022-43954 2023-02-16 18h05 +00:00 An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.
6.5
Medium