Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52824 | An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field. |
Solution
Please upgrade to FortiPortal version 7.2.1 or above Please upgrade to FortiPortal version 7.0.7 or above Please upgrade to FortiPortal version 6.0.15 or above Please upgrade to FortiPortal version 5.3.9 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-425 |
|
Mon, 02 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-12-02T14:29:38.033Z
Reserved: 2023-11-19T19:58:38.555Z
Link: CVE-2023-48791
Updated: 2024-08-02T21:37:54.980Z
Status : Modified
Published: 2023-12-13T07:15:28.980
Modified: 2024-11-21T08:32:26.740
Link: CVE-2023-48791
No data.
OpenCVE Enrichment
No data.
EUVD