CVE-2021-32590

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
fortinetfortiportal
3.2.0 ≤
𝑥
≤ 3.2.2
fortinetfortiportal
4.0.0 ≤
𝑥
≤ 4.0.4
fortinetfortiportal
4.1.0 ≤
𝑥
≤ 4.1.2
fortinetfortiportal
4.2.0 ≤
𝑥
≤ 4.2.4
fortinetfortiportal
5.0.0 ≤
𝑥
≤ 5.0.3
fortinetfortiportal
5.1.0 ≤
𝑥
≤ 5.1.2
fortinetfortiportal
5.2.0 ≤
𝑥
< 5.2.6
fortinetfortiportal
5.3.0 ≤
𝑥
< 5.3.6
fortinetfortiportal
6.0.0 ≤
𝑥
< 6.0.5
𝑥
= Vulnerable software versions