CVE-2023-48783
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
Una vulnerabilidad de omisión de autorización a través de clave controlada por el usuario [CWE-639] que afecta a PortiPortal versión 7.2.1 e inferior, versión 7.0.6 e inferior, versión 6.0.14 e inferior, versión 5.3.8 e inferior puede permitir que un usuario autenticado remotamente con al menos permisos de solo lectura para acceder a otros endpoints de la organización a través de solicitudes GET manipuladas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-11-19 CVE Reserved
- 2024-01-10 CVE Published
- 2024-01-18 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fortiguard.com/psirt/FG-IR-23-408 | 2024-01-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 5.3.0 <= 5.3.8 Search vendor "Fortinet" for product "Fortiportal" and version " >= 5.3.0 <= 5.3.8" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 6.0.0 <= 6.0.14 Search vendor "Fortinet" for product "Fortiportal" and version " >= 6.0.0 <= 6.0.14" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 7.0.0 < 7.0.7 Search vendor "Fortinet" for product "Fortiportal" and version " >= 7.0.0 < 7.0.7" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 7.2.0 < 7.2.2 Search vendor "Fortinet" for product "Fortiportal" and version " >= 7.2.0 < 7.2.2" | - |
Affected
|