Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3724 | An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests. |
Solution
Please upgrade to FortiPortal version 7.4.3 or above Please upgrade to FortiPortal version 7.2.7 or above Please upgrade to FortiPortal version 7.0.12 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-015 |
|
Wed, 23 Jul 2025 06:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* |
Wed, 12 Feb 2025 02:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Feb 2025 01:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests. | |
| Weaknesses | CWE-41 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-02-11T16:43:10.520Z
Reserved: 2025-01-21T20:48:07.886Z
Link: CVE-2025-24470
Updated: 2025-02-11T16:43:06.957Z
Status : Analyzed
Published: 2025-02-11T17:15:34.730
Modified: 2025-07-22T21:38:50.477
Link: CVE-2025-24470
No data.
OpenCVE Enrichment
Updated: 2025-07-13T20:07:11Z
EUVD