A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-52822 A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.
Fixes

Solution

Please upgrade to FortiPortal version 6.0.15 or above


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00336}

epss

{'score': 0.00425}


Thu, 02 Jan 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet
Fortinet fortiportal
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiportal

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2024-08-02T21:37:55.014Z

Reserved: 2023-11-19T19:58:38.554Z

Link: CVE-2023-48789

cve-icon Vulnrichment

Updated: 2024-08-02T21:37:55.014Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-03T08:15:08.507

Modified: 2025-01-02T18:33:37.333

Link: CVE-2023-48789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.