Exposure of password hashes to read-only admin

Summary

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb may allow an authenticated attacker to access the encrypted passwords of other administrators via the "Log Access Event" logs page.

Version Affected Solution
FortiWeb 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiWeb 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiWeb 7.2 7.2 all versions Migrate to a fixed release
FortiWeb 7.0 7.0 all versions Migrate to a fixed release
FortiWeb 6.4 Not affected Not Applicable
FortiWeb 6.3 6.3 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Mohamed Amine ZERIAT and Islem MEGHNINE for reporting this vulnerability under responsible disclosure.

Timeline

2024-11-12: Initial publication