← Back to browse · API

CVE-2021-32590

Severity
CRITICAL
CVSS
9.9
EPSS
0.01655
Risk score
40.18
CISA KEV
No
PoC
No
Published
2021-08-04
Modified
2024-10-25
First seen
2026-08-07
Aliases
EUVD-2021-19430, GHSA-CFM8-GGJG-Q9MJ
Products
Fortinet:Fortinet FortiPortal FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, 4.2.2 and earlier
Sources
euvd EUVD-2021-19430

Description

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests.

References