CVE-2025-24470: High severity fortinet fortiportal vulnerability
An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24470?
CVE-2025-24470 is considered a high severity vulnerability due to its potential for remote code retrieval by unauthenticated attackers.
How do I fix CVE-2025-24470?
To fix CVE-2025-24470, ensure you update FortiPortal to versions 7.4.3 or later, 7.2.7 or later, or 7.0.12 or later.
Who is affected by CVE-2025-24470?
CVE-2025-24470 affects FortiPortal versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, and 7.0.0 through 7.0.11.
What can attackers do with CVE-2025-24470?
With CVE-2025-24470, attackers can exploit the vulnerability to retrieve sensitive source code through specially crafted HTTP requests.
Is there a mitigation for CVE-2025-24470?
The primary mitigation for CVE-2025-24470 is to apply the recommended software updates as soon as possible.