CVE-2023-48791: Command Injection
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48791?
CVE-2023-48791 is classified as a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2023-48791?
To fix CVE-2023-48791, it is recommended to update FortiPortal to version 7.2.1 or higher, or to a patched version beyond 7.0.6.
Who is affected by CVE-2023-48791?
CVE-2023-48791 affects FortiPortal versions 7.0.6 and below, as well as version 7.2.0.
What type of vulnerability is CVE-2023-48791?
CVE-2023-48791 is a command injection vulnerability that allows unauthorized command execution.
What are the potential impacts of CVE-2023-48791?
CVE-2023-48791 could allow remote authenticated attackers to execute arbitrary commands on the affected FortiPortal systems.