CVE-2025-24470

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve

Severity
High 8.1
CVSS 3.1
Exploited
Not listed
EPSS
0.013
69.8th percentile
Discovered by
Third party
Vendor advisory field
Published
Feb 11, 2025
Assigned by fortinet

Description

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.

Weakness: CWE-41

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiPortal

Credit

Fortinet is pleased to thank Oliver Leo for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiPortal version 7.4.3 or above Please upgrade to FortiPortal version 7.2.7 or above Please upgrade to FortiPortal version 7.0.12 or above

Something wrong here?