Privilege escalation from low privilege administrator

Summary

An improper access control vulnerability [CWE-284] in FortiExtender authentication component may allow a remote authenticated attacker to create users with elevated privileges via a crafted HTTP request.

Version Affected Solution
FortiExtender 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiExtender 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiExtender 7.0 7.0.0 through 7.0.4 Upgrade to 7.0.5 or above
FortiExtender 4.2 Not affected Not Applicable

Acknowledgement

Discovered in the frame of internal audit by 3rd party company

Timeline

2024-07-09: Initial publication