VDB

CVE-2023-42783

CVE-2023-42783 PUBLISHED CVSS 5.300000190734863 MEDIUM

An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.

EPSS 0.90% · 57.5th percentile

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:F/RL:X/RC:C
EPSS Score
0.90%
57.5th percentile

Affected Products

VendorProductVersions
FortinetFortiMail7.2.0, 7.0.0, 6.4.0

Timeline

  • Nov 14, 2023 CVE Published
  • Nov 15, 2023 EPSS Score
  • Dec 16, 2023 EPSS Score
  • Jan 15, 2024 EPSS Score
  • Feb 15, 2024 EPSS Score
  • Mar 16, 2024 EPSS Score
  • Apr 16, 2024 EPSS Score
  • May 16, 2024 EPSS Score
  • Jun 16, 2024 EPSS Score
  • Jul 16, 2024 EPSS Score
  • Aug 16, 2024 EPSS Score
  • Aug 30, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›