Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortinet fortiportal vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-48789
A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 up to and including 6.0.14 allows malicious user to improper access control via crafted HTTP requests.
7.5
CVSSv3
CVE-2024-23105
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 up to and including 7.0.6 and version 7.2.0 up to and including 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
Fortinet Fortiportal
Fortinet Fortiportal 7.2.0
Fortinet Fortiportal 7.2.1
6.7
CVSSv3
CVE-2023-41842
A use of externally-controlled format string vulnerability [CWE-134] in Fortinet FortiManager version 7.4.0 up to and including 7.4.1, version 7.2.0 up to and including 7.2.3 and prior to 7.0.10, Fortinet FortiAnalyzer version 7.4.0 up to and including 7.4.1, version 7.2.0 up to ...
Fortinet Fortianalyzer
Fortinet Fortimanager
Fortinet Fortianalyzer Bigdata
Fortinet Fortianalyzer Bigdata 6.2.5
Fortinet Fortiportal
4.3
CVSSv3
CVE-2024-21761
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
Fortinet Fortiportal 7.2.0
Fortinet Fortiportal
5.4
CVSSv3
CVE-2023-48783
An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to acces...
Fortinet Fortiportal
8.8
CVSSv3
CVE-2023-46712
A improper access control in Fortinet FortiPortal version 7.0.0 up to and including 7.0.6, Fortinet FortiPortal version 7.2.0 up to and including 7.2.1 allows malicious user to escalate its privilege via specifically crafted HTTP requests.
Fortinet Fortiportal
8.8
CVSSv3
CVE-2023-48791
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands vi...
Fortinet Fortiportal
Fortinet Fortiportal 7.2.0
6.5
CVSSv3
CVE-2022-27490
A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 up to and including 6.0.4, FortiAnalyzer version 6.0.0 up to and including 6.0.4, FortiPortal version 6.0.0 up to and including 6.0.9, 5.3.0 up to and including 5.3.8, 5.2.x, 5.1.0...
Fortinet Fortiportal
Fortinet Fortimanager
Fortinet Fortianalyzer
Fortinet Fortiswitch
6.5
CVSSv3
CVE-2022-43954
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 up to and including 7.0.2 may allow a remote authenticated malicious user to read other devices' passwords in the audit log page.
Fortinet Fortiportal 7.0.2
Fortinet Fortiportal 7.0.1
Fortinet Fortiportal 7.0.0
4.8
CVSSv3
CVE-2022-41336
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 up to and including 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 management interface may allow a remote authenticated malicious user to perform a stored cross sit...
Fortinet Fortiportal
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »