Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-39945


An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).


Published

2022-11-02T12:15:54.973

Last Modified

2024-11-21T07:18:32.020

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortimail ≤ 6.0.12 Yes
Application fortinet fortimail ≤ 6.2.9 Yes
Application fortinet fortimail ≤ 6.4.7 Yes
Application fortinet fortimail ≤ 7.0.3 Yes
Application fortinet fortimail 7.2.0 Yes

References