CVE-2024-31495
Status: AnalyzedLow (2.7)—
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- Base score: 2.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.53%
- Percentile among all scored CVEs: 43
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-89
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-31495",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-31495",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-06-11T16:41:37.631630Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@fortinet.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "psirt@fortinet.com",
"affectedData": [
{
"vendor": "Fortinet",
"product": "FortiPortal",
"versions": [
{
"status": "affected",
"version": "7.2.0"
},
{
"status": "affected",
"version": "7.0.0",
"versionType": "semver",
"lessThanOrEqual": "7.0.6"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:fortinet:fortiportal:7.2.0:*:*:*:*:*:*:*"
],
"vendor": "fortinet",
"product": "fortiportal",
"versions": [
{
"status": "affected",
"version": "7.2.0"
}
],
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:2.3:a:fortinet:fortiportal:7.0.0:*:*:*:*:*:*:*"
],
"vendor": "fortinet",
"product": "fortiportal",
"versions": [
{
"status": "affected",
"version": "7.0.0",
"versionType": "custom",
"lessThanOrEqual": "7.0.6"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-06-11T15:16:05.697",
"references": [
{
"url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-128",
"tags": [
"Vendor Advisory"
],
"source": "psirt@fortinet.com"
},
{
"url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-128",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@fortinet.com",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality."
},
{
"lang": "es",
"value": "Una neutralización inadecuada de elementos especiales utilizados en un comando sql (\"inyección sql\") en las versiones 7.0.0 a 7.0.6 y 7.2.0 de Fortinet FortiPortal permite a un usuario privilegiado obtener información no autorizada a través de la funcionalidad de descarga de informes."
}
],
"lastModified": "2026-06-17T07:28:32.693",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "281311DE-FCED-4AB9-8D54-EBD0C8FE53B4",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortiportal:7.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C7F7D4E-DE62-491A-9C00-EAD2595BF2D7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@fortinet.com"
}