Blind SQL Injection

Summary

An improper neutralization of special elements used in a SQL Command [CWE-89] in FortiPortal may allow a priviledged user to obtain unauthorized information via the report download functionality.

Version Affected Solution
FortiPortal 7.2 7.2.0 Upgrade to 7.2.1 or above
FortiPortal 7.0 7.0.0 through 7.0.6 Upgrade to 7.0.7 or above
FortiPortal 6.0 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank David Cmara Galindo and Jose Catalan Tatay from Telefonica Tech for bringing this issue to our attention under responsible disclosure.

Timeline

2024-06-11: Initial publication