Products
Fortinet FortiPortal
- 7.0.0 through 7.0.6
- 7.2.0
Source
psirt@fortinet.com
Tags
CVE-2024-31495 details
Published : June 11, 2024, 3:16 p.m.
Last Modified : June 11, 2024, 3:16 p.m.
Last Modified : June 11, 2024, 3:16 p.m.
Description
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.
CVSS Score
1 | 2 | 3 | 4.3 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Base Score
4.3
Exploitability Score
Impact Score
Base Severity
MEDIUM
Vector String : CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References
URL | Source |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-128 | psirt@fortinet.com |
This website uses the NVD API, but is not approved or certified by it.