Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9h89-8jmf-g7hg

Опубликовано: 02 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).

An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).

EPSS

Процентиль: 41%
0.00187
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).

EPSS

Процентиль: 41%
0.00187
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639