Improper Authorization in FortiMail Webmail from Fortinet
CVE-2023-36633
5.3MEDIUM
What is CVE-2023-36633?
FortiMail webmail versions 7.2.0 to 7.2.2 and prior to 7.0.5 contain an improper authorization vulnerability that can be exploited by authenticated attackers. By crafting specific HTTP or HTTPS requests, these attackers can view and modify the titles of address book folders belonging to other users. This flaw raises concerns regarding the integrity and confidentiality of user data within the application.
Affected Version(s)
FortiMail 7.2.0 <= 7.2.2
FortiMail 7.0.0 <= 7.0.5
FortiMail 6.4.0 <= 6.4.8