Cross-Site Scripting Vulnerability in Fortinet FortiAnalyzer and FortiManager
CVE-2015-3620

Currently unrated

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
12 May 2015

Summary

A cross-site scripting vulnerability exists in the advanced dataset reports page of Fortinet's FortiAnalyzer and FortiManager products. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user session data and exposing sensitive information. Affected versions of FortiAnalyzer include 5.0.0 through 5.0.10 and 5.2.0 through 5.2.1, while FortiManager versions from 5.0.3 to 5.0.10 and 5.2.0 to 5.2.1 are also impacted. Proper security measures should be implemented to protect against potential exploit attempts.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.