CVE-2023-36633: Fortinet FortiMail
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
Affected products
- Fortinet FortiMail: from 6.0.0, before 7.0.6 (fixed in 7.0.6); from 7.2.0, before 7.2.3 (fixed in 7.2.3)
Published 2023-11-14. Last modified 2026-06-17.