Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c7f-7v62-c4p8

Опубликовано: 10 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.

An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.

EPSS

Процентиль: 42%
0.00197
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.

EPSS

Процентиль: 42%
0.00197
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-863