CVE-2021-42761
16.02.2023, 19:15
A conditionfor sessionfixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to infer the session identifier of other users and possibly usurp their session.Enginsight
Vendor | Product | Version |
---|---|---|
fortinet | fortiweb | 5.6.0 ≤ 𝑥 < 5.9.2 |
fortinet | fortiweb | 6.0.0 ≤ 𝑥 < 6.0.8 |
fortinet | fortiweb | 6.1.0 ≤ 𝑥 < 6.1.3 |
fortinet | fortiweb | 6.2.0 ≤ 𝑥 < 6.2.7 |
fortinet | fortiweb | 6.3.0 ≤ 𝑥 < 6.3.17 |
fortinet | fortiweb | 6.4.0 ≤ 𝑥 < 7.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration