An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices passwords in the audit log page.
The product writes sensitive information to a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortiportal | Fortinet | 7.0.0 (including) | 7.0.0 (including) |
Fortiportal | Fortinet | 7.0.1 (including) | 7.0.1 (including) |
Fortiportal | Fortinet | 7.0.2 (including) | 7.0.2 (including) |