CVE-2013-6826: Fortinet Fortianalyzer-1000d
Medium severity, CVSS 6.8. EPSS: 1.9% chance of exploitation in the next 30 days.
cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.
Affected products
- Fortinet Fortianalyzer-1000d
- Fortinet Fortianalyzer-2000b
- Fortinet Fortianalyzer-200d
- Fortinet Fortianalyzer-3000d
- Fortinet Fortianalyzer-300d
- Fortinet Fortianalyzer-4000b
- Fortinet Fortianalyzer Firmware: up to and including 5.0.4
Published 2013-11-20. Last modified 2026-06-17.