Multiple improper input validation and authorization vulnerabilities

Summary

Several improper input validation [CWE-20] and improper authorization vulnerabilities [CWE-285] affecting FortiWebManager may allow an authenticated attacker with at least read-only permission to execute unauthorized actions via HTTP requests or CLI. 

Version Affected Solution
FortiWebManager 7.4 Not affected Not Applicable
FortiWebManager 7.2 7.2.0 Upgrade to 7.2.1 or above
FortiWebManager 7.0 7.0.0 through 7.0.4 Upgrade to 7.0.5 or above
FortiWebManager 6.3 6.3.0 Upgrade to 6.3.1 or above
FortiWebManager 6.2 6.2.3 through 6.2.4 Upgrade to 6.2.5 or above
FortiWebManager 6.0 6.0.2 Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank security researchers Zach Hanley (@hacks_zach) of Horizon3.ai for discovering and reporting this vulnerability under responsible disclosure.

Timeline

2024-05-14: Initial publication