A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to infer the session identifier of other users and possibly usurp their session.
2023-02-16T19:15:11.603
2024-11-21T06:28:07.163
Modified
CVSSv3.1: 9.0 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiweb | < 5.9.2 | Yes |
Application | fortinet | fortiweb | < 6.0.8 | Yes |
Application | fortinet | fortiweb | < 6.1.3 | Yes |
Application | fortinet | fortiweb | < 6.2.7 | Yes |
Application | fortinet | fortiweb | < 6.3.17 | Yes |
Application | fortinet | fortiweb | < 7.0.0 | Yes |