A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-353 |
![]() ![]() |
History
Tue, 11 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests. | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published: 2025-03-11T14:54:31.599Z
Updated: 2025-03-11T16:05:58.718Z
Reserved: 2023-11-19T19:58:38.554Z
Link: CVE-2023-48790

Updated: 2025-03-11T16:03:37.344Z

Status : Received
Published: 2025-03-11T15:15:40.227
Modified: 2025-03-11T15:15:40.227
Link: CVE-2023-48790

No data.