CVE-2017-7337 is an improper access control vulnerability affecting Fortinet FortiPortal versions 4.0.0 and below. An unauthenticated attacker can exploit this flaw to interact with unauthorized VDOMs or enumerate other ADOMs by leveraging stolen session and CSRF tokens or manipulating the 'adomName' parameter in specific requests. With a CVSS score of 9.1 (CRITICAL), this vulnerability allows for high impact to confidentiality and integrity with low attack complexity, requiring no user interaction. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0.0CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.