Lucene search

K
fortinetFortiGuard LabsFG-IR-17-279
HistoryMar 06, 2018 - 12:00 a.m.

FortiWeb's cookie tampering protection can be bypassed by erasing the FortiWeb session cookie

2018-03-0600:00:00
FortiGuard Labs
www.fortiguard.com
10

EPSS

0.001

Percentile

48.7%

An improper access control vulnerability in FortiWeb’s Signed Security mode may allow an attacker to disable the cookie tampering protection offered by FortiWeb (to sites FortiWeb protects), via deleting FortiWeb’s session cookie.

EPSS

0.001

Percentile

48.7%

Related for FG-IR-17-279