First published: Wed Jan 10 2024(Updated: )
A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPortal | >=7.0.0<=7.0.6 | |
Fortinet FortiPortal | >=7.2.0<=7.2.1 |
Please upgrade to FortiPortal version 7.2.2 Please upgrade to FortiPortal version 7.0.7
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46712 is considered a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2023-46712, upgrade Fortinet FortiPortal to version 7.0.7 or 7.2.2 or later.
FortiPortal versions 7.0.0 through 7.0.6 and 7.2.0 through 7.2.1 are affected by CVE-2023-46712.
CVE-2023-46712 allows attackers to escalate their privileges through specially crafted HTTP requests.
Organizations using affected versions of Fortinet FortiPortal may be vulnerable to CVE-2023-46712.