PT-2024-19041 · Fortinet · Fortiportal

Published

2024-03-12

·

Updated

2024-03-21

·

CVE-2024-21761

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiPortal versions 7.0.6 and below FortiPortal version 7.2.0
Description An improper authorization issue in FortiPortal may allow a user to download other organizations' reports via modification in the request payload. This issue could potentially be exploited by modifying the request to access unauthorized data.
Recommendations For FortiPortal versions 7.0.6 and below, update to a version above 7.0.6 to resolve the issue. For FortiPortal version 7.2.0, update to a version above 7.2.0 to resolve the issue. As a temporary workaround, consider restricting access to the report download functionality to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-21761

Affected Products

Fortiportal