Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortinet fortiportal vulnerabilities and exploits
(subscribe to this query)
3.1
CVSSv3
CVE-2021-36181
A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal prior to 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data into an inco...
Fortinet Fortiportal
6.1
CVSSv3
CVE-2021-32602
An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below, 5.3.6 and below, 5.2.6 and below, 5.1.2 and below, 5.0.3 and below, 4.2.2 and below, 4.1.2 and below, 4.0.4 and below may allow a remote and unauthenticated m...
Fortinet Fortiportal
9.1
CVSSv3
CVE-2017-7337
An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an malicious user to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen session and CSRF tokens or the adomName parameter in the /fpc/sec/custome...
Fortinet Fortiportal
8.1
CVSSv3
CVE-2021-36171
The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal prior to 6.0.6 may allow a remote unauthenticated malicious user to predict parts of or the whole newly generated password within a given time frame.
Fortinet Fortiportal
8.1
CVSSv3
CVE-2021-36172
An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal prior to 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from t...
Fortinet Fortiportal
7.5
CVSSv3
CVE-2021-36174
A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal prior to 6.0.6 may allow an malicious user to perform a denial of service attack via specially crafted license blobs.
Fortinet Fortiportal
6.1
CVSSv3
CVE-2021-36176
Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal prior to 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests.
Fortinet Fortiportal
9.8
CVSSv3
CVE-2021-32588
A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated malicious user to execute unauthorized commands as root by uploading and deploying ma...
Fortinet Fortiportal
7.5
CVSSv3
CVE-2021-32596
A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 up to and including 6.04 may allow an attacker already in possession of the password store to decrypt the passwords by means of precomputed tables.
Fortinet Fortiportal
8.8
CVSSv3
CVE-2023-46712
A improper access control in Fortinet FortiPortal version 7.0.0 up to and including 7.0.6, Fortinet FortiPortal version 7.2.0 up to and including 7.2.1 allows malicious user to escalate its privilege via specifically crafted HTTP requests.
Fortinet Fortiportal
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »