Insecure Direct Object Reference in policy API Endpoint

Summary

An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortiportal organization interface may allow an authenticated attacker to view resources of other organizations via HTTP or HTTPS requests.

Version Affected Solution
FortiPortal 7.2 7.2.0 Upgrade to 7.2.1 or above
FortiPortal 7.0 7.0.0 through 7.0.6 Upgrade to 7.0.7 or above

Timeline

2024-07-09: Initial publication