An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
2024-07-09T16:15:04.357
2024-11-21T08:54:57.347
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiportal | < 7.0.7 | Yes |
Application | fortinet | fortiportal | 7.2.0 | Yes |