CVE-2018-1354
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.7%
exploitation probability
1.7%top 25% of all CVEs
observed exploitation
nono source reports it
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
Affected products
Fortinet, Inc. · Fortinet FortiManager, FortiAnalyzer