PT-2024-19041 · Fortinet · Fortiportal
Published
2024-03-12
·
Updated
2024-03-21
·
CVE-2024-21761
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiPortal versions 7.0.6 and below
FortiPortal version 7.2.0
Description
An improper authorization issue in FortiPortal may allow a user to download other organizations' reports via modification in the
request payload. This issue could potentially be exploited by modifying the request to access unauthorized data.Recommendations
For FortiPortal versions 7.0.6 and below, update to a version above 7.0.6 to resolve the issue.
For FortiPortal version 7.2.0, update to a version above 7.2.0 to resolve the issue.
As a temporary workaround, consider restricting access to the report download functionality to minimize the risk of exploitation.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiportal