An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-18-389 | Mitigation Vendor Advisory |
https://www.fortiguard.com/psirt/FG-IR-20-231 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: fortinet
Published: 2019-06-04T20:33:53
Updated: 2021-06-03T10:28:48
Reserved: 2018-07-06T00:00:00
Link: CVE-2018-13382
JSON object: View
NVD Information
Status : Modified
Published: 2019-06-04T21:29:00.373
Modified: 2021-06-03T11:15:08.413
Link: CVE-2018-13382
JSON object: View
Redhat Information
No data.
CWE