First published: Tue Jul 09 2024(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities [CWE-352] in FortiAIOps version 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of an authenticated user via tricking the victim to execute malicious GET requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAIOps | =2.0.0 |
Please upgrade to FortiAIOps version 2.0.1 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27783 has a high severity rating due to its potential impact on authenticated users through arbitrary actions by attackers.
To fix CVE-2024-27783, users should upgrade FortiAIOps to a patched version that addresses these CSRF vulnerabilities.
CVE-2024-27783 affects all users of FortiAIOps version 2.0.0.
CVE-2024-27783 is associated with cross-site request forgery (CSRF) attacks.
Yes, CVE-2024-27783 can be exploited remotely by unauthenticated attackers.