CVE-2019-17651 — Cross-site Scripting in Fortinet Fortisiem
Severity
5.4MEDIUMNVD
EPSS
0.2%
top 57.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 28
Latest updateMay 24
Description
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedule.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-vpwg-c4h3-2hjj: An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5↗2022-05-24
CVEList▶
CVE-2019-17651: An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5↗2020-01-28
📋Vendor Advisories
1Fortinet▶
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedu...↗2020-01-28