An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Forticlient | Fortinet | 6.4.0 (including) | 6.4.6 (including) |
Forticlient | Fortinet | 6.2.7 (including) | 6.2.7 (including) |
Forticlient | Fortinet | 7.0.0 (including) | 7.0.0 (including) |