cbcvebase.
CVE-2015-7363
published 2016-10-07

CVE-2015-7363: Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models…

medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrators to inject arbitrary web script or HTML via vectors related to report filters.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortianalyzer_firmware
fortinetfortimanager_firmware
fortinetfortimanager_firmware
fortinetfortimanager_firmware
fortinetfortimanager_firmware
fortinetfortimanager_firmware
fortinetfortimanager_firmware
fortinetfortimanager_firmware
fortinetfortimanager_firmware
fortinetfortimanager_firmware