A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-086 |
![]() ![]() |
History
Fri, 31 Jan 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fortinet
Fortinet fortiportal |
|
CPEs | cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* | |
Vendors & Products |
Fortinet
Fortinet fortiportal |
Tue, 14 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 14 Jan 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request. | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published: 2025-01-14T14:09:45.115Z
Updated: 2025-01-14T16:51:29.678Z
Reserved: 2024-05-14T21:15:19.190Z
Link: CVE-2024-35278

Updated: 2025-01-14T16:51:24.379Z

Status : Analyzed
Published: 2025-01-14T14:15:30.280
Modified: 2025-01-31T17:09:31.407
Link: CVE-2024-35278

No data.