High severity8.8NVD Advisory· Published Oct 10, 2023· Updated Jun 17, 2026
CVE-2023-36556
CVE-2023-36556
Description
An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.
Affected products
6cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.12
- cpe:2.3:a:fortinet:fortimail:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortimail:7.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortimail:7.2.2:*:*:*:*:*:*:*
- (no CPE)range: 7.2.0 through 7.2.2, 7.0.0 through 7.0.5 and below 6.4.7
- (no CPE)range: 7.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-202nvdVendor Advisory
News mentions
0No linked articles in our index yet.