CVE-2023-48783: Medium severity fortinet fortiportal vulnerability
An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48783?
CVE-2023-48783 is classified as a medium severity vulnerability due to its impact on data access.
How do I fix CVE-2023-48783?
To fix CVE-2023-48783, upgrade your FortiPortal installation to version 7.2.2 or later.
What versions of FortiPortal are affected by CVE-2023-48783?
CVE-2023-48783 affects FortiPortal versions 5.3.8 and below, 6.0.14 and below, 7.0.6 and below, and 7.2.1 and below.
Who can exploit CVE-2023-48783?
CVE-2023-48783 can be exploited by remote authenticated users with at least read-only permissions.
What kind of vulnerability is CVE-2023-48783?
CVE-2023-48783 is an Authorization Bypass Through User-Controlled Key vulnerability.