Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-31495


A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.


Published

2024-06-11T15:16:05.697

Last Modified

2025-01-02T18:27:26.153

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiportal < 7.0.7 Yes
Application fortinet fortiportal 7.2.0 Yes

References