Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3724 | An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests. |
Solution
Please upgrade to FortiPortal version 7.4.3 or above Please upgrade to FortiPortal version 7.2.7 or above Please upgrade to FortiPortal version 7.0.12 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-015 |
|
Tue, 22 Jul 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* |
Tue, 11 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests. | |
| Weaknesses | CWE-41 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-02-11T16:43:10.520Z
Reserved: 2025-01-21T20:48:07.886Z
Link: CVE-2025-24470
Updated: 2025-02-11T16:43:06.957Z
Status : Analyzed
Published: 2025-02-11T17:15:34.730
Modified: 2025-07-22T21:38:50.477
Link: CVE-2025-24470
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:07:11Z
EUVD