Client-side enforcement of server-side security related to customer reports features

Summary

Client-side enforcement of server-side security vulnerability [CWE-602] in FortiPortal may allow an authenticated attacker with a customer account to access other customers information via crafted HTTP requests.

Version Affected Solution
FortiPortal 7.2 Not affected Not Applicable
FortiPortal 7.0 Not affected Not Applicable
FortiPortal 6.0 6.0.0 through 6.0.14 Upgrade to 6.0.15 or above

Timeline

2024-05-14: Initial publication
2024-05-14: Fixed typo in title