First published: Wed Dec 08 2021(Updated: )
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWeb | >=6.3.0<=6.3.15 | |
Fortinet FortiWeb | =6.4.0 | |
Fortinet FortiWeb | =6.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-41013.
The severity of CVE-2021-41013 is medium with a score of 5.3.
FortiWeb versions 6.4.1 and below and 6.3.15 and below are affected by CVE-2021-41013.
An unauthorized user can exploit the vulnerability by accessing the Log reports via their URLs in the Report Browse section of Log & Report.
Yes, Fortinet has released patches to fix CVE-2021-41013. Please refer to the FortiGuard advisory for more information.