Incorrect user management in widgets dashboard

Summary

An Incorrect User Management vulnerability [CWE-286] in FortiWeb widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests.

Version Affected Solution
FortiWeb 7.6 7.6.0 through 7.6.2 Upgrade to 7.6.3 or above
FortiWeb 7.4 7.4.0 through 7.4.6 Upgrade to 7.4.7 or above
FortiWeb 7.2 7.2.0 through 7.2.10 Upgrade to 7.2.11 or above
FortiWeb 7.0 7.0 all versions Migrate to a fixed release
FortiWeb 6.4 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Islem MEGHNINE and Mohamed Amine ZERIAT for reporting this vulnerability under responsible disclosure.

Timeline

2025-04-08: Initial publication