Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-35557 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request. |
Solution
Please upgrade to FortiPortal version 7.4.0 or above Please upgrade to FortiPortal version 7.2.5 or above Please upgrade to FortiPortal version 7.0.9 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-086 |
|
Fri, 31 Jan 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortiportal |
|
| CPEs | cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortiportal |
Tue, 14 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jan 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-01-14T16:51:29.678Z
Reserved: 2024-05-14T21:15:19.190Z
Link: CVE-2024-35278
Updated: 2025-01-14T16:51:24.379Z
Status : Analyzed
Published: 2025-01-14T14:15:30.280
Modified: 2025-01-31T17:09:31.407
Link: CVE-2024-35278
No data.
OpenCVE Enrichment
No data.
EUVD