First published: Tue Nov 14 2023(Updated: )
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
|Affected Software||Affected Version||How to fix|
CVE-2023-36633 is an improper authorization vulnerability in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.6.
CVE-2023-36633 allows an authenticated attacker to see and modify the title of address book folders of other users in FortiMail.
The severity of CVE-2023-36633 is medium with a CVSS score of 5.3.
To fix CVE-2023-36633, it is recommended to upgrade FortiMail webmail to a version that is not affected by the vulnerability (7.2.3 or above).
More information about CVE-2023-36633 can be found at the following link: [FortiGuard Advisory](https://fortiguard.com/psirt/FG-IR-23-203)