A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.
Solution:
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Link | Tags |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-406 | vendor advisory |