An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-23-357 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: fortinet
Published: 2024-02-15T13:59:23.728Z
Updated: 2024-07-09T17:08:17.614Z
Reserved: 2023-10-09T08:01:29.296Z
Link: CVE-2023-45581
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-02-15T14:15:45.033
Modified: 2024-02-20T20:54:47.437
Link: CVE-2023-45581
JSON object: View
Redhat Information
No data.