An improper authorization vulnerability [CWE-285] in Fortinet FortiOS version 7.4.0 through 7.4.1 and before 7.2.8 & Fortinet FortiProxy before version 7.4.8 allows an authenticated attacker to access static files of others VDOMs via crafted HTTP or HTTPS requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortios | 7.0.0 | 7.2.9 |
| fortinet / fortios | 7.4.0 | 7.4.2 |
| fortinet / fortiproxy | 2.0.0 | 7.4.9 |