First published: Tue Jan 14 2025(Updated: )
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPortal | >=6.0.0<=6.0.14 | |
Fortinet FortiPortal | >=6.0.0<6.0.15 |
Please upgrade to FortiPortal version 6.0.15 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52967 has been classified as a high severity vulnerability due to its potential for allowing unauthorized code execution.
To fix CVE-2024-52967, you should upgrade Fortinet FortiPortal to version 6.0.15 or later.
CVE-2024-52967 affects Fortinet FortiPortal versions from 6.0.0 through 6.0.14.
CVE-2024-52967 is classified as a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of script-related HTML tags.
By exploiting CVE-2024-52967, attackers can execute unauthorized commands or code through HTML injection.