Sensitive Information Exposure in Fortinet FortiPortal by Fortinet
CVE-2025-46777
2.2LOW
What is CVE-2025-46777?
Fortinet FortiPortal versions 7.4.0, 7.2.0 to 7.2.5, and 7.0.0 to 7.0.9 suffer from a vulnerability that allows authenticated users with read-only admin permissions to access sensitive information stored in system logs. This flaw could expose encrypted secrets through unprotected log files, potentially leading to further exploitation. It highlights the importance of securing logging mechanisms to protect sensitive data from unauthorized access.
Affected Version(s)
FortiPortal 7.4.0
FortiPortal 7.2.0 <= 7.2.5
FortiPortal 7.0.0 <= 7.0.9