CVE-2023-48790

Severity
8.8HIGH
EPSS
0.0%
top 94.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11

Description

A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortindr1.5.07.0.6+3
CVEListV5fortinet/fortindr7.1.07.1.1+4

🔴Vulnerability Details

2
GHSA
GHSA-fcjw-j93v-hxxq: A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 72025-03-11
CVEList
CVE-2023-48790: A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 72025-03-11

📋Vendor Advisories

1
Fortinet
A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 t...2025-03-11
CVE-2023-48790 (HIGH CVSS 8.8) | A cross site request forgery vulner | cvebase.io