Description


Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests.

Related CPE's


a

fortinet

fortiweb

5

Weaknesses



CWE-285


NVD-CWE-noinfo

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

5.9 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2024-06-03T10:15:12.870Z

2 years ago

Last modified

2026-06-17T07:13:20.367Z

2 months ago