CVE-2017-7342

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
25/03/2019
Last modified:
26/03/2019

Description

A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close button

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* 4.0.0 (including)


References to Advisories, Solutions, and Tools