CRITICAL🇵🇱 Wersja polska

CVE-2017-7337

CVSS 9.1v3.0pub. 2017-05-27upd. 2026-05-13

An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen session and CSRF tokens or the adomName parameter in the /fpc/sec/customer/policy/getAdomVersion request.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Fortinet Fortiportal

    APP
    Fortinet
    ≤ 4.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-32588CRITICAL9.8PL ✓same product

Zakodowane na stałe poświadczenia w Fortinet FortiPortal umożliwiają RCE jako root

CVE-2021-32590CRITICAL9.9PL ✓same product

SQL Injection w Fortinet FortiPortal umożliwiający wykonanie dowolnych poleceń na bazie danych

CVE-2017-7342CRITICAL9.8PL ✓same product

Słaby mechanizm odzyskiwania hasła w Fortinet FortiPortal umożliwia nieautoryzowane wykonanie kodu

CVE-2025-24470HIGH8.6same product

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 th...

CVE-2021-32589HIGH8.1same product

A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7...