First published: Tue Nov 14 2023(Updated: )
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiMail | >=6.0.0<7.0.6 | |
Fortinet FortiMail | >=7.2.0<7.2.3 |
Please upgrade to FortiMail version 7.4.0 or above Please upgrade to FortiMail version 7.2.3 or above Please upgrade to FortiMail version 7.0.6 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36633 is an improper authorization vulnerability in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.6.
CVE-2023-36633 allows an authenticated attacker to see and modify the title of address book folders of other users in FortiMail.
The severity of CVE-2023-36633 is medium with a CVSS score of 5.3.
To fix CVE-2023-36633, it is recommended to upgrade FortiMail webmail to a version that is not affected by the vulnerability (7.2.3 or above).
More information about CVE-2023-36633 can be found at the following link: [FortiGuard Advisory](https://fortiguard.com/psirt/FG-IR-23-203)