Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortiportal vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2024-23105
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 up to and including 7.0.6 and version 7.2.0 up to and including 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
Fortinet Fortiportal
Fortinet Fortiportal 7.2.0
Fortinet Fortiportal 7.2.1
6.5
CVSSv3
CVE-2022-43954
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 up to and including 7.0.2 may allow a remote authenticated malicious user to read other devices' passwords in the audit log page.
Fortinet Fortiportal 7.0.2
Fortinet Fortiportal 7.0.1
Fortinet Fortiportal 7.0.0
4.3
CVSSv3
CVE-2024-21761
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
Fortinet Fortiportal 7.2.0
Fortinet Fortiportal
8.8
CVSSv3
CVE-2023-48791
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands vi...
Fortinet Fortiportal
Fortinet Fortiportal 7.2.0
8.1
CVSSv3
CVE-2021-32594
An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 up to and including 6.0.4, 5.3.0 up to and including 5.3.5, 5.2.0 up to and including 5.2.5, and 4.2.2 and previous versions may allow a low-privileged user to potentially tamper with the underlyi...
Fortinet Fortiportal
6.1
CVSSv3
CVE-2021-32602
An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below, 5.3.6 and below, 5.2.6 and below, 5.1.2 and below, 5.0.3 and below, 4.2.2 and below, 4.1.2 and below, 4.0.4 and below may allow a remote and unauthenticated m...
Fortinet Fortiportal
6.5
CVSSv3
CVE-2021-36168
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x prior to 6.0.5, FortiPortal 5.3.x prior to 5.3.6 and any FortiPortal prior to 6.2.5 allows authenticated malicious user to disclosure information via crafted GET...
Fortinet Fortiportal
9.1
CVSSv3
CVE-2017-7337
An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an malicious user to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen session and CSRF tokens or the adomName parameter in the /fpc/sec/custome...
Fortinet Fortiportal
8.8
CVSSv3
CVE-2021-32590
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 up to and including 6.0.4, 5.3.0 up to and including 5.3.5, 5.2.0 up to and including 5.2.5, and 4.2.2 and previous versions may allow an attacker with regular user...
Fortinet Fortiportal
4.8
CVSSv3
CVE-2022-41336
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 up to and including 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 management interface may allow a remote authenticated malicious user to perform a stored cross sit...
Fortinet Fortiportal
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
CVE-2012-1823
memory leak
CVE-2024-0627
CVE-2024-31402
privilege escalation
CVE-2024-36418
remote code execution
CVE-2024-27844
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »