CVE-2024-35278

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-14 14:15

Updated : 2025-01-31 17:09


NVD link : CVE-2024-35278

Mitre link : CVE-2024-35278

CVE.ORG link : CVE-2024-35278


JSON object : View

Products Affected

fortinet

  • fortiportal
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')