FG-IR-24-274: Insufficient Access Control Over API Endpoints
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiPortal may allow an authenticated attacker to view unauthorized device information via key modification in API requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-274?
The severity of FG-IR-24-274 is considered significant as it allows authenticated attackers to bypass authorization and access unauthorized device information.
How do I fix FG-IR-24-274?
To fix FG-IR-24-274, upgrade FortiPortal to version 7.4.1 or later, or apply the patches for versions 7.2.6 or 7.0.9 as specified by Fortinet.
Who is affected by FG-IR-24-274?
FortiPortal users running versions below 7.4.1, 7.2.6, or 7.0.9 are affected by the FG-IR-24-274 vulnerability.
What kind of vulnerability is FG-IR-24-274?
FG-IR-24-274 is an authorization bypass through user-controlled key vulnerability, classified under CWE-639.
What can attackers do with FG-IR-24-274?
Attackers exploiting FG-IR-24-274 can view unauthorized device information through key modification in API requests.