Description
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiPortal version 7.2.1 or above Please upgrade to FortiPortal version 7.0.7 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19375 | An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-24-016 |
|
History
No history.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-12T18:03:23.595Z
Reserved: 2024-01-02T10:15:00.527Z
Link: CVE-2024-21761
Updated: 2024-08-01T22:27:36.303Z
Status : Modified
Published: 2024-03-12T15:15:48.740
Modified: 2024-11-21T08:54:57.477
Link: CVE-2024-21761
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD