Improper Access Control Flaw in Fortinet FortiSOAR Product
CVE-2023-25605
7.5HIGH
What is CVE-2023-25605?
An improper access control vulnerability exists in Fortinet's FortiSOAR, versions 7.3.0 and 7.3.1. This flaw allows an attacker who is already authenticated to the administrative interface to execute unauthorized actions by sending specially crafted HTTP requests. It highlights the risks posed by insufficient access controls and underscores the importance of robust security measures to safeguard administrative interfaces from unauthorized manipulation.
Affected Version(s)
FortiSOAR 7.3.0 <= 7.3.1