CVE Published: 27/06/2018 |
CVE Updated: 25/10/2024 |
CVE Year: 2018 Source: fortinet |
Vendor: Fortinet, Inc. |
Product: Fortinet FortiManager, FortiAnalyzer Status : PUBLISHED
CVE-2018-1354 Description
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.