CVE-2016-4066

Description

Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote attackers to hijack the authentication of administrators for requests that change the password via unspecified vectors.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.136

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-4066 ,CVE-2016-5092 are affected in fortiweb 5.5.2NCM
Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-4066)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234