mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
19 lines
931 B
Markdown
19 lines
931 B
Markdown
### [CVE-2024-45323](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45323)
|
||

|
||

|
||

|
||

|
||
|
||
### Description
|
||
|
||
An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
No PoCs from references.
|
||
|
||
#### Github
|
||
- https://github.com/fkie-cad/nvd-json-data-feeds
|
||
|