Description
An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.
Published: 2024-11-12
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Please upgrade to FortiPortal version 7.2.0 or above Please upgrade to FortiPortal version 7.0.4 or above

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-51654 An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.
History

Thu, 02 Jan 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet
Fortinet fortiportal
CPEs cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiportal

Wed, 13 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 19:00:00 +0000

Type Values Removed Values Added
Description An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:U/RC:C'}


Subscriptions

Fortinet Fortiportal
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2024-11-13T18:28:05.032Z

Reserved: 2023-11-06T10:35:25.828Z

Link: CVE-2023-47543

cve-icon Vulnrichment

Updated: 2024-11-13T18:28:00.315Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-12T19:15:07.110

Modified: 2025-01-02T18:29:53.643

Link: CVE-2023-47543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses