CVE-2018-1354: Medium severity fortinet fortianalyzer vulnerability
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1354?
CVE-2018-1354 is an improper access control vulnerability in Fortinet FortiManager and FortiAnalyzer versions 6.0.0, 5.6.5, and below.
How does CVE-2018-1354 affect Fortinet FortiManager?
CVE-2018-1354 allows a regular user to edit the avatar picture of other users with arbitrary content on Fortinet FortiManager versions 6.0.0, 5.6.5, and below.
How does CVE-2018-1354 affect Fortinet FortiAnalyzer?
CVE-2018-1354 allows a regular user to edit the avatar picture of other users with arbitrary content on Fortinet FortiAnalyzer versions 6.0.0, 5.6.5, and below.
What is the severity of CVE-2018-1354?
CVE-2018-1354 has a severity rating of 6.5 (medium).
What is the Common Weakness Enumeration (CWE) ID of CVE-2018-1354?
The CWE ID of CVE-2018-1354 is CWE-732.