CVE-2024-46671: Incorrect user management in widgets dashboard
An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests.
Other sources
An Incorrect User Management vulnerability [CWE-286] in FortiWeb widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46671?
CVE-2024-46671 is considered to have a high severity due to the potential for authenticated users with read-only admin permissions to manipulate the dashboard.
How do I fix CVE-2024-46671?
To fix CVE-2024-46671, update your FortiWeb to version 7.6.3 or later, version 7.4.7 or later, version 7.2.11 or later, or version 7.0.12 or later.
Who is affected by CVE-2024-46671?
CVE-2024-46671 affects FortiWeb versions 7.6.2 and below, 7.4.6 and below, 7.2.10 and below, and 7.0.11 and below.
What types of operations can be performed due to CVE-2024-46671?
Due to CVE-2024-46671, an authenticated attacker can perform unauthorized operations on the dashboard.
Is there a workaround for CVE-2024-46671 before applying the fix?
Currently, there are no documented workarounds for CVE-2024-46671, so upgrading to a secure version is recommended.