CVE Vulnerabilities

CVE-2023-27998

Missing Custom Error Page

Published: Sep 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.

Weakness

The product does not return custom error pages to the user, possibly exposing sensitive information.

Affected Software

NameVendorStart VersionEnd Version
FortipresenceFortinet1.0.0 (including)1.0.0 (including)
FortipresenceFortinet1.1.0 (including)1.1.0 (including)
FortipresenceFortinet1.1.1 (including)1.1.1 (including)
FortipresenceFortinet1.2.0 (including)1.2.0 (including)
FortipresenceFortinet1.2.1 (including)1.2.1 (including)

References