CVE-2022-39945Authorization Bypass Through User-Controlled Key in Fortinet Fortimail

Severity
6.5MEDIUMNVD
CNA5.4
EPSS
0.2%
top 59.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2

Description

An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 1.2 | Impact: 5.2

Affected Packages2 packages

NVDfortinet/fortimail6.0.06.0.12+4
CVEListV5fortinet/fortinet_fortimailFortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions

🔴Vulnerability Details

2
GHSA
GHSA-9h89-8jmf-g7hg: An improper access control vulnerability [CWE-284] in FortiMail 72022-11-02
CVEList
CVE-2022-39945: An improper access control vulnerability [CWE-284] in FortiMail 72022-11-02

📋Vendor Advisories

1
Fortinet
An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all ve...2022-11-02
CVE-2022-39945 — Fortinet Fortimail vulnerability | cvebase