THREATOPS
THREAT OPSThreat News › [NVD] CVE-2023-42787 (MEDIUM 6.5) — A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side co

[NVD] CVE-2023-42787 (MEDIUM 6.5) — A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side co

lownvdPublished 2023-10-10

CVE-2023-42787 CVSS: 6.5 MEDIUM Published: 2023-10-10T17:15:12.930

A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-42787