Home
HIGH: 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:X/RC:XDefault status
unaffected
7.4.0
affected
7.2.0 (semver)
affected
7.1.0 (semver)
affected
7.0.0 (semver)
affected
1.5.0 (semver)
affected
Description
A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests.
Problem types
Execute unauthorized code or commands
Product status
7.4.0
7.2.0 (semver)
7.1.0 (semver)
7.0.0 (semver)
1.5.0 (semver)
References
fortiguard.fortinet.com/psirt/FG-IR-23-353