CVE-2024-21761: Medium severity fortinet fortiportal vulnerability
Published Mar 12, 2024
·Updated
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
Affected Software
2 affected components
Fortinet FortiPortal>=7.0.0<7.0.7
Fortinet FortiPortal=7.2.0
Remediation
Information
Please upgrade to FortiPortal version 7.2.1 or above
Please upgrade to FortiPortal version 7.0.7 or above
Event History
Mar 12, 2024
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21761?
CVE-2024-21761 is classified as a high severity vulnerability.
2
How do I fix CVE-2024-21761?
To fix CVE-2024-21761, update FortiPortal to version 7.0.7 or higher, or 7.2.1 and above.
3
Who is affected by CVE-2024-21761?
CVE-2024-21761 affects users of FortiPortal versions 7.0.6 and below, as well as version 7.2.0.
4
What is the impact of CVE-2024-21761?
The impact of CVE-2024-21761 may allow unauthorized users to access and download reports from other organizations.
5
What type of vulnerability is CVE-2024-21761?
CVE-2024-21761 is categorized as an improper authorization vulnerability.