Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3qf-ph3j-w487

Опубликовано: 10 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.

An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.

EPSS

Процентиль: 39%
0.00176
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 3.7
nvd
больше 3 лет назад

An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.

CVSS3: 5.9
fstec
больше 3 лет назад

Уязвимость графического интерфейса программного средства для централизованного управления устройствами Fortinet FortiManager и межсетевого экрана FortiAnalyzer, позволяющая нарушителю получить доступ к шаблонам отчетов

EPSS

Процентиль: 39%
0.00176
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-668