Cross-Site Scripting Vulnerability in Fortinet FortiManager and FortiAnalyzer
CVE-2016-3193
5.4MEDIUM
What is CVE-2016-3193?
A cross-site scripting vulnerability exists in the web applications of Fortinet's FortiManager and FortiAnalyzer, specifically affecting various versions of these products. This vulnerability enables remote authenticated users to inject arbitrary web scripts or HTML into applications due to poorly sanitized inputs. Attackers could exploit this flaw through unspecified vectors, potentially leading to unauthorized actions being performed within the context of the affected applications. Users are advised to apply the necessary updates to mitigate the risks associated with this vulnerability.