Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortinet fortiportal vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-43954
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 up to and including 7.0.2 may allow a remote authenticated malicious user to read other devices' passwords in the audit log page.
Fortinet Fortiportal 7.0.2
Fortinet Fortiportal 7.0.1
Fortinet Fortiportal 7.0.0
NA
CVE-2024-21761
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
Fortinet Fortiportal 7.2.0
Fortinet Fortiportal
NA
CVE-2023-48791
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands vi...
Fortinet Fortiportal
Fortinet Fortiportal 7.2.0
641
VMScore
CVE-2021-26104
Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, and FortiPo...
Fortinet Fortimanager
Fortinet Fortianalyzer
Fortinet Fortiportal
NA
CVE-2022-27490
A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 up to and including 6.0.4, FortiAnalyzer version 6.0.0 up to and including 6.0.4, FortiPortal version 6.0.0 up to and including 6.0.9, 5.3.0 up to and including 5.3.8, 5.2.x, 5.1.0...
Fortinet Fortiportal
Fortinet Fortimanager
Fortinet Fortianalyzer
Fortinet Fortiswitch
356
VMScore
CVE-2021-36168
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x prior to 6.0.5, FortiPortal 5.3.x prior to 5.3.6 and any FortiPortal prior to 6.2.5 allows authenticated malicious user to disclosure information via crafted GET...
Fortinet Fortiportal
605
VMScore
CVE-2021-36171
The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal prior to 6.0.6 may allow a remote unauthenticated malicious user to predict parts of or the whole newly generated password within a given time frame.
Fortinet Fortiportal
570
VMScore
CVE-2021-36172
An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal prior to 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from t...
Fortinet Fortiportal
445
VMScore
CVE-2021-36174
A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal prior to 6.0.6 may allow an malicious user to perform a denial of service attack via specially crafted license blobs.
Fortinet Fortiportal
383
VMScore
CVE-2021-36176
Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal prior to 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests.
Fortinet Fortiportal
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48654
CVE-2024-2757
authentication bypass
CVE-2024-3194
CVE-2024-33640
CVE-2024-21111
dos
insecure direct object reference
CVE-2024-21345
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »