imPC@ndo IT

Tracker / CVE-2025-46777

CVE-2025-46777

Low 2.3

A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin permissions to view encrypted secrets via the FortiPortal System Log.

Affected products and versions

fortinet fortiportal
fortinet fortiportal · 7.0.0 → 7.0.10
fortinet fortiportal · 7.2.0 → 7.2.6

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References