Fortinet FortiPortal 7.2.1

CPE Details

Fortinet FortiPortal 7.2.1
7.2.1
2024-01-17
13h40 +00:00
2024-01-17
13h40 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:fortinet:fortiportal:7.2.1:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortiportal

Version

7.2.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-35278 2025-01-14 14h09 +00:00 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
4.3
Moyen
CVE-2024-23105 2024-05-14 16h19 +00:00 A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
7.5
Haute
CVE-2023-48783 2024-01-10 17h51 +00:00 An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
5.4
Moyen
CVE-2023-46712 2024-01-10 17h51 +00:00 A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
8.8
Haute