CVE-2024-31495

Publication date

2024-06-11 14:31:58

Family

fortinet

State

PUBLISHED

Description

A improper neutralization of special elements used in an sql command (sql injection) in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.