Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10307 | An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests. |
Solution
Please upgrade to FortiWeb version 7.6.3 or above Please upgrade to FortiWeb version 7.4.7 or above Please upgrade to FortiWeb version 7.2.11 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-184 |
|
Thu, 24 Jul 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* |
Tue, 08 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests. | |
| Weaknesses | CWE-286 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-04-08T14:30:24.831Z
Reserved: 2024-09-11T12:14:59.206Z
Link: CVE-2024-46671
Updated: 2025-04-08T14:30:20.742Z
Status : Analyzed
Published: 2025-04-08T14:15:31.740
Modified: 2025-07-24T19:57:38.407
Link: CVE-2024-46671
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:44:35Z
EUVD