Vulnerabilities > Fortinet > Fortiportal > 7.2.1

DATE CVE VULNERABILITY TITLE RISK
2025-01-14 CVE-2024-35278 SQL Injection vulnerability in Fortinet Fortiportal
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
network
low complexity
fortinet CWE-89
4.3
2024-05-14 CVE-2024-23105 Unspecified vulnerability in Fortinet Fortiportal
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
network
high complexity
fortinet
7.5
2024-01-10 CVE-2023-46712 Unspecified vulnerability in Fortinet Fortiportal
A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
network
low complexity
fortinet
8.8
2024-01-10 CVE-2023-48783 Unspecified vulnerability in Fortinet Fortiportal
An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
network
low complexity
fortinet
5.4