Fortinet FortiPortal
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*
- >= 7.2.0, <= 7.2.4
- >= 7.0.0, <= 7.2.8
A SQL injection vulnerability has been identified in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8. This vulnerability arises from improper neutralization of special elements used in SQL commands, which may allow an authenticated attacker to view SQL queries being executed on the server side. The issue can be exploited by including special elements in an HTTP request.
Exploitation of this vulnerability could lead to unauthorized disclosure of SQL queries being executed on the server, potentially allowing attackers to infer sensitive database information or manipulate database queries.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.