Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of an authenticated user via tricking the victim to execute malicious GET requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-070 | Vendor Advisory |
| https://fortiguard.fortinet.com/psirt/FG-IR-24-070 | Vendor Advisory |
Configurations
History
09 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of an authenticated user via tricking the victim to execute malicious GET requests. |
21 Nov 2024, 09:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-070 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.6 |
16 Aug 2024, 14:46
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fortinet:fortiaiops:2.0.0:*:*:*:*:*:*:* | |
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-070 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| First Time |
Fortinet fortiaiops
Fortinet |
|
| Summary |
|
09 Jul 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-07-09 16:15
Updated : 2026-01-09 17:15
NVD link : CVE-2024-27783
Mitre link : CVE-2024-27783
CVE.ORG link : CVE-2024-27783
JSON object : View
Products Affected
fortinet
- fortiaiops
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
