CVE-2023-48789: Medium severity fortinet fortiportal vulnerability
Published Jun 3, 2024
·Updated
A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.
Affected Software
1 affected component
Fortinet FortiPortal>=6.0.0<6.0.15
Remediation
Information
Please upgrade to FortiPortal version 6.0.15 or above
Event History
Jun 3, 2024
CVE Published
via MITRE·07:57 AM
Data Sourced
via MITRE·07:57 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-48789?
CVE-2023-48789 is classified as a high severity vulnerability that allows improper access control.
2
How do I fix CVE-2023-48789?
To resolve CVE-2023-48789, you should upgrade Fortinet FortiPortal to version 6.0.15 or later.
3
What are the affected software versions for CVE-2023-48789?
CVE-2023-48789 affects Fortinet FortiPortal versions from 6.0.0 to 6.0.14.
4
What type of attack does CVE-2023-48789 allow?
CVE-2023-48789 allows attackers to perform unauthorized access through crafted HTTP requests.
5
Is CVE-2023-48789 a client-side or server-side vulnerability?
CVE-2023-48789 is a client-side enforcement issue of server-side security.