VYPR
High severity8.8NVD Advisory· Published Oct 10, 2023· Updated Jun 17, 2026

CVE-2023-36556

CVE-2023-36556

Description

An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.

Affected products

6
  • cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.12
    • cpe:2.3:a:fortinet:fortimail:7.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:7.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:7.2.2:*:*:*:*:*:*:*
    • (no CPE)range: 7.2.0 through 7.2.2, 7.0.0 through 7.0.5 and below 6.4.7
    • (no CPE)range: 7.2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.