A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
History

Fri, 31 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet
Fortinet fortiportal
CPEs cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiportal

Tue, 14 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jan 2025 14:15:00 +0000

Type Values Removed Values Added
Description A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2025-01-14T16:51:29.678Z

Reserved: 2024-05-14T21:15:19.190Z

Link: CVE-2024-35278

cve-icon Vulnrichment

Updated: 2025-01-14T16:51:24.379Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-14T14:15:30.280

Modified: 2025-01-31T17:09:31.407

Link: CVE-2024-35278

cve-icon Redhat

No data.