An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortimanager | Fortinet | * | 6.0.6 (including) |
Fortimanager | Fortinet | 6.2.0 (including) | 6.2.0 (including) |
Fortimanager | Fortinet | 6.2.1 (including) | 6.2.1 (including) |