Insecure Direct Object Reference over API endpoints

Summary

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiPortal administrative interface may allow an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.

Version Affected Solution
FortiPortal 7.4 Not affected Not Applicable
FortiPortal 7.2 Not affected Not Applicable
FortiPortal 7.0 7.0.0 through 7.0.3 Upgrade to 7.0.4 or above
FortiPortal 6.0 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2024-11-12: Initial publication