An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2022-10-10T00:00:00

Updated: 2024-08-03T04:56:37.398Z

Reserved: 2022-02-25T00:00:00

Link: CVE-2022-26121

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-10T14:15:09.727

Modified: 2022-10-12T18:44:41.780

Link: CVE-2022-26121

cve-icon Redhat

No data.