peter bassill · operator
$ cve CVE-2013-6826 JSON

CVE-2013-6826 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.93% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2013-11-20
Last modified2026-06-17

Affected (7)

VendorProduct
fortinetfortianalyzer firmware
fortinetfortianalyzer-1000d
fortinetfortianalyzer-2000b
fortinetfortianalyzer-200d
fortinetfortianalyzer-3000d
fortinetfortianalyzer-300d
fortinetfortianalyzer-4000b

Public exploits

SourceTitleDate
exploit-dbFortinet FortiAnalyzer - Cross-Site Request Forgery2013-10-12

References

→ the Explorer  ·  watch your stack  ·  NVD