CVE-2021-32590: SQL Injection
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-32590.
What is the severity of CVE-2021-32590?
The severity of CVE-2021-32590 is critical with a severity value of 8.8.
What is the affected software?
The affected software is FortiPortal versions 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier.
How can an attacker exploit this vulnerability?
An attacker with regular user's privileges can exploit this vulnerability to execute arbitrary commands on the underlying SQL database.
How can I fix CVE-2021-32590?
To fix CVE-2021-32590, it is recommended to update to a patched version of FortiPortal.