Missing authorization on CSV user import
Summary
A missing authorization vulnerability [CWE-862] in FortiAuthenticator may allow a read-only admin to make modification to local users via a file upload to an unprotected endpoint.
| Version | Affected | Solution |
|---|---|---|
| FortiAuthenticator 8.0 | Not affected | Not Applicable |
| FortiAuthenticator 6.6 | 6.6.0 through 6.6.6 | Upgrade to 6.6.7 or above |
| FortiAuthenticator 6.5 | 6.5 all versions | Migrate to a fixed release |
| FortiAuthenticator 6.4 | 6.4 all versions | Migrate to a fixed release |
| FortiAuthenticator 6.3 | 6.3 all versions | Migrate to a fixed release |