Medium severity5.4NVD Advisory· Published Nov 14, 2023· Updated Jun 17, 2026
CVE-2023-36633
CVE-2023-36633
Description
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
Affected products
3Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-203nvdVendor Advisory
News mentions
0No linked articles in our index yet.