CVE-2017-17541

Severity
6.1MEDIUM
EPSS
0.2%
top 62.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateMay 14

Description

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-cp34-9454-rv45: A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 62022-05-14
CVEList
CVE-2017-17541: A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 62018-07-16

📋Vendor Advisories

1
Fortinet
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0...2018-07-16
CVE-2017-17541 (MEDIUM CVSS 6.1) | A Cross-site Scripting (XSS) vulner | cvebase.io