SQL Query Returned in FortiView Response

Summary

An improper neutralization of special elements used in a SQL command [CWE-89] in FortiPortal may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request

Version Affected Solution
FortiPortal 7.4 Not affected Not Applicable
FortiPortal 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiPortal 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above

Acknowledgement

Fortinet is pleased to thank David Cámara Galindo and Jose Catalan Tatay by Telefonica Tech for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication
2025-01-14: removing FAZ from table
2025-01-14: fix spelling errors