An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-23-202 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: fortinet

Published: 2023-10-10T16:49:50.906Z

Updated: 2023-10-10T16:49:50.906Z

Reserved: 2023-06-23T14:57:30.033Z


Link: CVE-2023-36556

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-10-10T17:15:12.140

Modified: 2023-11-07T04:16:37.820


Link: CVE-2023-36556

JSON object: View

cve-icon Redhat Information

No data.

CWE