A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close button
Fortinet
Exploit
CVE-2017-7342
NVD
Update to v4.0.0 | Fortinet PSIRT Advisory