Cross-Site Scripting Vulnerability in Fortinet FortiAnalyzer and FortiManager
CVE-2015-3620
Currently unrated
Summary
A cross-site scripting vulnerability exists in the advanced dataset reports page of Fortinet's FortiAnalyzer and FortiManager products. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user session data and exposing sensitive information. Affected versions of FortiAnalyzer include 5.0.0 through 5.0.10 and 5.2.0 through 5.2.1, while FortiManager versions from 5.0.3 to 5.0.10 and 5.2.0 to 5.2.1 are also impacted. Proper security measures should be implemented to protect against potential exploit attempts.
References
Timeline
Vulnerability published
Vulnerability Reserved