An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-51654 An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.
Fixes

Solution

Please upgrade to FortiPortal version 7.2.0 or above Please upgrade to FortiPortal version 7.0.4 or above


Workaround

No workaround given by the vendor.

History

Thu, 02 Jan 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet
Fortinet fortiportal
CPEs cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiportal

Wed, 13 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 19:00:00 +0000

Type Values Removed Values Added
Description An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:U/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2024-11-13T18:28:05.032Z

Reserved: 2023-11-06T10:35:25.828Z

Link: CVE-2023-47543

cve-icon Vulnrichment

Updated: 2024-11-13T18:28:00.315Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-12T19:15:07.110

Modified: 2025-01-02T18:29:53.643

Link: CVE-2023-47543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.