Cross Site Request Forgery in admin endpoint

Summary

A cross site request forgery vulnerability [CWE-352] in FortiNDR may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests.

Version Affected Solution
FortiNDR 7.6 Not affected Not Applicable
FortiNDR 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiNDR 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiNDR 7.1 7.1.0 through 7.1.1 Upgrade to upcoming 7.1.2 or above
FortiNDR 7.0 7.0.0 through 7.0.5 Upgrade to 7.0.6 or above
FortiNDR 1.5 1.5 all versions Migrate to a fixed release
FortiNDR 1.4 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Dipanjan Das of Fortinet Vulnerability Research team.

Timeline

2025-03-11: Initial publication