Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests.
2024-06-03T10:15:12.870
2024-12-17T16:43:37.527
Analyzed
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiweb | ≤ 6.3.23 | Yes |
Application | fortinet | fortiweb | ≤ 6.4.3 | Yes |
Application | fortinet | fortiweb | ≤ 7.0.10 | Yes |
Application | fortinet | fortiweb | < 7.2.8 | Yes |
Application | fortinet | fortiweb | < 7.4.3 | Yes |