FG-IR-24-184: Incorrect user management in widgets dashboard
An Incorrect User Management vulnerability [CWE-286] in FortiWeb widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-184?
The FG-IR-24-184 vulnerability is classified as a medium severity due to its potential impact on user management in FortiWeb.
How do I fix FG-IR-24-184?
To fix FG-IR-24-184, ensure that FortiWeb is updated to version 7.6.3 or later, 7.4.7 or later, or 7.2.11 or later, depending on your current version.
Who is affected by FG-IR-24-184?
FG-IR-24-184 affects authenticated users with read-only admin permissions in Fortinet's FortiWeb dashboard.
What type of vulnerability is FG-IR-24-184?
FG-IR-24-184 is an Incorrect User Management vulnerability classified under CWE-286.
Can an attacker exploit FG-IR-24-184 remotely?
Yes, an authenticated attacker can exploit FG-IR-24-184 remotely through crafted requests to perform unauthorized operations.