An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 up to and including 7.2.2 and prior to 7.0.5 allows an authenticated malicious user to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
fortinet fortimail |