Client-side enforcement of server-side security related to customer reports features
Summary
Client-side enforcement of server-side security vulnerability [CWE-602] in FortiPortal may allow an authenticated attacker with a customer account to access other customers information via crafted HTTP requests.
| Version | Affected | Solution |
|---|---|---|
| FortiPortal 7.2 | Not affected | Not Applicable |
| FortiPortal 7.0 | Not affected | Not Applicable |
| FortiPortal 6.0 | 6.0.0 through 6.0.14 | Upgrade to 6.0.15 or above |
Timeline
2024-05-14: Initial publication2024-05-14: Fixed typo in title