Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-52824 | An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field. |
Solution
Please upgrade to FortiPortal version 7.2.1 or above Please upgrade to FortiPortal version 7.0.7 or above Please upgrade to FortiPortal version 6.0.15 or above Please upgrade to FortiPortal version 5.3.9 or above
Workaround
No workaround given by the vendor.
Link | Providers |
---|---|
https://fortiguard.com/psirt/FG-IR-23-425 |
![]() ![]() |
Mon, 02 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-12-02T14:29:38.033Z
Reserved: 2023-11-19T19:58:38.555Z
Link: CVE-2023-48791

Updated: 2024-08-02T21:37:54.980Z

Status : Modified
Published: 2023-12-13T07:15:28.980
Modified: 2024-11-21T08:32:26.740
Link: CVE-2023-48791

No data.

No data.