Fortinet FortiPortal
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*
- >= 7.4.0, <= 7.4.7
- >= 7.2.0, <= 7.2.8
- ~7.0
A vulnerability allowing improper access control has been identified in Fortinet FortiPortal versions 7.4.0 through 7.4.7, 7.2.0 through 7.2.8, and all versions of 7.0. This vulnerability may allow a remote privileged attacker with an organization user role to access sensitive network configuration data by sending crafted HTTP requests to certain API endpoints.
Exploitation of this vulnerability could lead to unauthorized access to sensitive network configuration data.
Users of Fortinet FortiPortal 7.4 should upgrade to version 7.4.8 or above. Users of Fortinet FortiPortal 7.2 should upgrade to version 7.2.9 or above. Users of Fortinet FortiPortal 7.0 should migrate to a fixed release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.