Home

Description

A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close button

PUBLISHED Reserved 2017-03-30 | Published 2019-03-25 | Updated 2024-10-25 | Assigner fortinet

Problem types

Password

Product status

FortiPortal versions 4.0.0 and below
affected

References

fortiguard.com/psirt/FG-IR-17-114

cve.org (CVE-2017-7342)

nvd.nist.gov (CVE-2017-7342)

Download JSON