CVE-2023-36633: Medium severity fortinet fortimail-200d vulnerability
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-36633?
CVE-2023-36633 is an improper authorization vulnerability in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.6.
How does CVE-2023-36633 affect FortiMail?
CVE-2023-36633 allows an authenticated attacker to see and modify the title of address book folders of other users in FortiMail.
What is the severity of CVE-2023-36633?
The severity of CVE-2023-36633 is medium with a CVSS score of 5.3.
How can I fix CVE-2023-36633?
To fix CVE-2023-36633, it is recommended to upgrade FortiMail webmail to a version that is not affected by the vulnerability (7.2.3 or above).
Where can I find more information about CVE-2023-36633?
More information about CVE-2023-36633 can be found at the following link: [FortiGuard Advisory](https://fortiguard.com/psirt/FG-IR-23-203)