Cross-Site Request Forgery Vulnerability in Fortinet FortiAnalyzer
CVE-2013-6826

Currently unrated

What is CVE-2013-6826?

A vulnerability in Fortinet FortiAnalyzer, specifically in the cgi-bin/module//sysmanager/admin/SYSAdminUserDialog endpoint, has been identified where the csrf_token parameter is not adequately validated. This oversight enables remote attackers to exploit this flaw, executing unauthorized actions on behalf of legitimate users through cross-site request forgery (CSRF) attacks. It is crucial for organizations using affected versions to implement security measures to mitigate potential risks of unauthorized access and manipulation of their systems.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.