CVE-2024-52967: Fortinet Fortiportal

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection.

Affected products

  • Fortinet Fortiportal: from 6.0.0, before 6.0.15 (fixed in 6.0.15)

Published 2025-01-14. Last modified 2026-06-17.