CVE-2013-6826
cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.
- Affected products
- Fortianalyzer
- Fortinet Fortianalyzer Firmware
- ≤ 5.0.4
- Fortinet fortianalyzer-1000d
- All versions
- Fortinet fortianalyzer-2000b
- All versions
- Fortinet fortianalyzer-200d
- All versions
- Fortinet fortianalyzer-3000d
- All versions
- Fortinet fortianalyzer-300d
- All versions
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 1.9% (79th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2013-11-19
CVE-2013-6826 at NVD
1 known exploit for CVE-2013-6826
Proof-of-concept code and exploit modules indexed by Sploitus