Inter-domain information leakage

Summary

An improper access control vulnerability [CWE-284] in FortiMail may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).

Version Affected Solution
FortiMail 7.2 7.2.0 Upgrade to 7.2.1 or above
FortiMail 7.0 7.0.0 through 7.0.3 Upgrade to 7.0.4 or above
FortiMail 6.4 6.4 all versions Migrate to a fixed release
FortiMail 6.2 6.2 all versions Migrate to a fixed release
FortiMail 6.0 6.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Abdulmohsen Naser Alotaibi from National Information Center - Deem for reporting this vulnerability under responsible disclosure.

Timeline

2022-11-01: Initial publication