Inter-domain information leakage
Summary
An improper access control vulnerability [CWE-284] in FortiMail may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).
| Version | Affected | Solution |
|---|---|---|
| FortiMail 7.2 | 7.2.0 | Upgrade to 7.2.1 or above |
| FortiMail 7.0 | 7.0.0 through 7.0.3 | Upgrade to 7.0.4 or above |
| FortiMail 6.4 | 6.4 all versions | Migrate to a fixed release |
| FortiMail 6.2 | 6.2 all versions | Migrate to a fixed release |
| FortiMail 6.0 | 6.0 all versions | Migrate to a fixed release |
Acknowledgement
Fortinet is pleased to thank Abdulmohsen Naser Alotaibi from National Information Center - Deem for reporting this vulnerability under responsible disclosure.
Timeline
2022-11-01: Initial publication