CVE-2024-31495: SQL Injection
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31495?
CVE-2024-31495 is classified as a high-severity vulnerability due to its potential for unauthorized information access.
How do I fix CVE-2024-31495?
To mitigate CVE-2024-31495, upgrade Fortinet FortiPortal to version 7.0.7 or later, or version 7.2.1 or later.
Who is affected by CVE-2024-31495?
CVE-2024-31495 affects users of Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0.
What type of vulnerability is CVE-2024-31495?
CVE-2024-31495 is an SQL injection vulnerability that allows privileged users to exploit the report download feature.
What can attackers do with CVE-2024-31495?
Attackers exploiting CVE-2024-31495 can obtain unauthorized information through the FortiPortal report download functionality.