VYPR
Medium severity6.2NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026

CVE-2024-46671

CVE-2024-46671

Description

An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Fortinet/Fortiweb3 versions
    cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=7.0.0,<7.2.11
    • (no CPE)range: <=7.6.2, <=7.4.6, <=7.2.10, <=7.0.11
    • (no CPE)range: 7.6.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.