Account creation outside initial IdP
Summary
An improper privilege management vulnerability [CWE-269] in FortiPortal may allow a remote and authenticated attacker to add users outside its initial Idp
Affected Products
FortiPortal version 7.2.0 through 7.2.1FortiPortal version 7.0.0 through 7.0.6
FortiPortal 6.0 all versions are not affected
FortiPortal 5.3 all versions are not affected
Solutions
Please upgrade to FortiPortal version 7.2.2
Please upgrade to FortiPortal version 7.0.7