cbcvebase.
CVE-2024-46671
published 2025-04-08

CVE-2024-46671: An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and…

PriorityP344high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.42%
34.3th percentile
An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests.

Affected

8 ranges
VendorProductVersion rangeFixed in
fortinetfortiweb
fortinetfortiweb>= 7.0.0 < 7.2.117.2.11
fortinetfortiweb7.0.0 – 7.0.11
fortinetfortiweb7.2.0 – 7.2.10
fortinetfortiweb>= 7.4.0 < 7.4.77.4.7
fortinetfortiweb7.4.0 – 7.4.6
fortinetfortiweb>= 7.6.0 < 7.6.37.6.3
fortinetfortiweb7.6.0 – 7.6.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.