CVE-2024-21759
An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
Severity
Low 3.9
CVSS 3.1
Exploited
Not listed
EPSS
0.003
22.2th percentile
Discovered by
Third party
Vendor advisory field
Published
Jul 9, 2024
Assigned by fortinet
Description
An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
Weakness: CWE-639
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiPortal | Network & Security Management | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiPortal
- fortinet · fortiportal
Credit
External
Vendor remediation
Please upgrade to FortiPortal version 7.4.0 or above Please upgrade to FortiPortal version 7.2.3 or above Please upgrade to FortiPortal version 7.0.8 or above