CVE-2024-52967: XSS
Published Jan 14, 2025
·Updated
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection.
Affected Software
2 affected components
Fortinet FortiPortal>=6.0.0<=6.0.14
Fortinet FortiPortal>=6.0.0<6.0.15
Remediation
Information
Please upgrade to FortiPortal version 6.0.15 or above
Event History
Jan 14, 2025
CVE Published
via MITRE·02:09 PM
Data Sourced
via MITRE·02:09 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 10, 57065
Event
via NVD·09:56 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-52967?
CVE-2024-52967 has been classified as a high severity vulnerability due to its potential for allowing unauthorized code execution.
2
How do I fix CVE-2024-52967?
To fix CVE-2024-52967, you should upgrade Fortinet FortiPortal to version 6.0.15 or later.
3
What versions of Fortinet FortiPortal are affected by CVE-2024-52967?
CVE-2024-52967 affects Fortinet FortiPortal versions from 6.0.0 through 6.0.14.
4
What type of vulnerability is CVE-2024-52967?
CVE-2024-52967 is classified as a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of script-related HTML tags.
5
What can attackers achieve by exploiting CVE-2024-52967?
By exploiting CVE-2024-52967, attackers can execute unauthorized commands or code through HTML injection.