CVE-2024-21759

An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.

Severity
Low 3.9
CVSS 3.1
Exploited
Not listed
EPSS
0.003
21.5th percentile
Discovered by
Not disclosed
Published
Jul 9, 2024
Assigned by fortinet

Description

An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.

Weakness: CWE-639

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported affected versions (2)
  • Fortinet · FortiPortal
  • fortinet · fortiportal

Vendor remediation

Please upgrade to FortiPortal version 7.4.0 or above Please upgrade to FortiPortal version 7.2.3 or above Please upgrade to FortiPortal version 7.0.8 or above