First published: Wed Dec 13 2023(Updated: )
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPortal | >=7.0.0<=7.0.6 | |
Fortinet FortiPortal | =7.2.0 |
Please upgrade to FortiPortal version 7.2.1 or above Please upgrade to FortiPortal version 7.0.7 or above Please upgrade to FortiPortal version 6.0.15 or above Please upgrade to FortiPortal version 5.3.9 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.