An Improper Privilege Management vulnerability [CWE-269]...
Moderate severity
Unreviewed
Published
Jun 10, 2025
to the GitHub Advisory Database
•
Updated Jun 10, 2025
Description
Published by the National Vulnerability Database
Jun 10, 2025
Published to the GitHub Advisory Database
Jun 10, 2025
Last updated
Jun 10, 2025
An Improper Privilege Management vulnerability [CWE-269] affecting Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16 and before 6.4.15, FortiProxy version 7.6.0 through 7.6.1 and before 7.4.7 & FortiWeb version 7.6.0 through 7.6.1 and before 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.
References