A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-288 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Nov 2023, 04:10
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-13 13:15
Updated : 2023-11-07 04:10
NVD link : CVE-2023-27998
Mitre link : CVE-2023-27998
JSON object : View
Products Affected
fortinet
- fortipresence
CWE
CWE-755
Improper Handling of Exceptional Conditions