Fortinet FortiPortal是美国飞塔(Fortinet)公司的FortiGate、FortiWiFi 和 FortiAP 产品线的高级、功能丰富的托管安全分析和管理支持工具,可作为虚拟机供 MSP 使用。 FortiPortal若干版本存在安全漏洞,该漏洞源于其管理接口的无效输入可能会允许经过身份验证的远程攻击者通过发送带有特制柱索引参数的请求来执行存储型跨站脚本。以下版本受到影响:6.0.0至6.0.11版本和5.3、5.2、5.1、5.0的所有版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fortinet | FortiPortal | 6.0.0 ~ 6.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39947 | 8.6 HIGH | Fortinet FortiADC 操作系统命令注入漏洞 |
| CVE-2022-35845 | 7.6 HIGH | FortiTester 操作系统命令注入漏洞 |
| CVE-2022-42471 | 5.3 MEDIUM | Fortinet FortiWeb 注入漏洞 |
No comments yet