Cross-Site Request Forgery Vulnerability in Fortinet FortiAnalyzer
CVE-2013-6826

Currently unrated

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
20 November 2013

Summary

A vulnerability in Fortinet FortiAnalyzer, specifically in the cgi-bin/module//sysmanager/admin/SYSAdminUserDialog endpoint, has been identified where the csrf_token parameter is not adequately validated. This oversight enables remote attackers to exploit this flaw, executing unauthorized actions on behalf of legitimate users through cross-site request forgery (CSRF) attacks. It is crucial for organizations using affected versions to implement security measures to mitigate potential risks of unauthorized access and manipulation of their systems.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.