> Authentication bypass via invalid parameter
[DATE: 12/08/2025 07:00]
[LANGUAGE: EN]
An improper handling of parameters [CWE-233] vulnerability in FortiWeb may allow an unauthenticated remote attacker in possession of non-public information (pertaining to both the device and to the targeted user) to log in as any existing user on the device via a specially crafted request. Revised on 2025-08-12 00:00:00