Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortinet fortiportal vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2021-36168
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x prior to 6.0.5, FortiPortal 5.3.x prior to 5.3.6 and any FortiPortal prior to 6.2.5 allows authenticated malicious user to disclosure information via crafted GET...
Fortinet Fortiportal
8.8
CVSSv3
CVE-2021-32590
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 up to and including 6.0.4, 5.3.0 up to and including 5.3.5, 5.2.0 up to and including 5.2.5, and 4.2.2 and previous versions may allow an attacker with regular user...
Fortinet Fortiportal
8.1
CVSSv3
CVE-2021-32594
An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 up to and including 6.0.4, 5.3.0 up to and including 5.3.5, 5.2.0 up to and including 5.2.5, and 4.2.2 and previous versions may allow a low-privileged user to potentially tamper with the underlyi...
Fortinet Fortiportal
9.8
CVSSv3
CVE-2017-7342
A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an malicious user to execute unauthorized code or commands via a hidden Close button
Fortinet Fortiportal
6.1
CVSSv3
CVE-2017-7340
A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an malicious user to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.
Fortinet Fortiportal
7.5
CVSSv3
CVE-2017-7338
A password management vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an malicious user to carry out information disclosure via the FortiAnalyzer Management View.
Fortinet Fortiportal
6.1
CVSSv3
CVE-2017-7339
A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an malicious user to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality.
Fortinet Fortiportal
6.1
CVSSv3
CVE-2017-7343
An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows malicious user to execute unauthorized code or commands via the url parameter.
Fortinet Fortiportal
7.5
CVSSv3
CVE-2017-7731
A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows malicious user to carry out information disclosure via the Forgotten Password feature.
Fortinet Fortiportal
9.1
CVSSv3
CVE-2017-7337
An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an malicious user to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen session and CSRF tokens or the adomName parameter in the /fpc/sec/custome...
Fortinet Fortiportal
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3