cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortianalyzer_firmware | - | 5.0.4.x |