Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Fortinet PortiPortal 安全漏洞
Vulnerability Description
Fortinet PortiPortal是美国飞塔(Fortinet)公司的一个基于云的多租户门户。用于安全策略管理和分析。 Fortinet PortiPortal 7.2.1版本及之前版本、7.0.6版本及之前版本、6.0.14版本及之前版本、5.3.8版本存在安全漏洞。攻击者利用该漏洞通过特制的 GET 请求访问其他组织端点的只读权限。
CVSS Information
N/A
Vulnerability Type
N/A