imPC@ndo IT

Tracker / CVE-2013-6826

CVE-2013-6826

Medium 6.8

cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.

Affected products and versions

fortinet fortianalyzer-1000d
fortinet fortianalyzer-2000b
fortinet fortianalyzer-200d
fortinet fortianalyzer-3000d
fortinet fortianalyzer-300d
fortinet fortianalyzer-4000b
fortinet fortianalyzer_firmware · … → 5.0.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References