CVE-2025-24470

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve

Severity
High 8.1
CVSS 3.1
Exploited
Not listed
EPSS
0.013
67.2th percentile
Discovered by
Not disclosed
Published
Feb 11, 2025
Assigned by fortinet

Description

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.

Weakness: CWE-41

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiPortal

Vendor remediation

Please upgrade to FortiPortal version 7.4.3 or above Please upgrade to FortiPortal version 7.2.7 or above Please upgrade to FortiPortal version 7.0.12 or above