An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit repo containing one Python exploit script and one README. The main file, CVE-2024-46671.py, uses the requests library to interact with a Fortinet FortiWeb appliance over HTTPS. It is not part of a larger exploit framework. The script flow is: normalize the target URL to HTTPS, test connectivity, authenticate to /logincheck with provided credentials, query /api/v2.0/system/state to assess whether the target may be vulnerable and to retrieve a CSRF token, enumerate admin users via /api/v2.0/cmdb/system/admin, and then issue repeated DELETE requests against /api/v2.0/system/status.dashboard_widget using a crafted mkey pattern. The README describes the bug as an authenticated IDOR/logical vulnerability in FortiWeb 7.4.3 build 638 (GA) that can lead to account deletion and recreation of a default admin account with no password after reboot. The exploit is operational rather than a mere PoC because it automates the full authenticated abuse chain, but it uses a fixed workflow rather than a flexible framework payload. Notable code quality issues exist: the script references JSON keys spelled as 'resutls' instead of 'results' in multiple places, and delete_widgets is passed the full users list but indexes target_user[2], implying it expects at least three users and only targets one derived username. Despite these implementation flaws, the intended capability and target API surface are clear.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.