CVE-2023-36633
5.4MEDIUMAn improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders
Published: 11/14/2023Updated: 11/21/2024
Description
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
AI AnalysisPowered by AI
Affected Products
fortinetfortimail
fortinetfortimail
References
- https://fortiguard.com/psirt/FG-IR-23-203Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-23-203Vendor Advisory