An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.
2023-02-16T19:15:13.650
2024-11-21T07:27:24.510
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiportal | 7.0.0 | Yes |
Application | fortinet | fortiportal | 7.0.1 | Yes |
Application | fortinet | fortiportal | 7.0.2 | Yes |