Fortinet FortiPortal 7.2.0

CPE Details

Fortinet FortiPortal 7.2.0
7.2.0
2023-12-16
02h37 +00:00
2023-12-16
02h37 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:fortinet:fortiportal:7.2.0:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortiportal

Version

7.2.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-35278 2025-01-14 14h09 +00:00 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
4.3
Moyen
CVE-2024-21759 2024-07-09 15h33 +00:00 An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
4.3
Moyen
CVE-2024-31495 2024-06-11 14h31 +00:00 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.
4.3
Moyen
CVE-2024-23105 2024-05-14 16h19 +00:00 A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
7.5
Haute
CVE-2024-21761 2024-03-12 15h09 +00:00 An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
4.3
Moyen
CVE-2023-48783 2024-01-10 17h51 +00:00 An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
5.4
Moyen
CVE-2023-46712 2024-01-10 17h51 +00:00 A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
8.8
Haute
CVE-2023-48791 2023-12-13 06h45 +00:00 An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.
8.8
Haute