Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.
CVSS v2.0 Score
3.5
/ 10.0
LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
Information
- Published
- 2 févr. 2015
- Updated
- 12 avr. 2025
- Status
- Deferred
- Source
- cve@mitre.org
Affected products
fortinet fortiosAll Fortinet FortiOS CVEs →
Versions : 5.0.7
Weaknesses (CWE)
CWE-79
References (10)
- http://www.fortiguard.com/advisory/FG-IR-15-002/Vendor Advisory
- http://www.fortiguard.com/advisory/FG-IR-15-002/Vendor Advisory
Similar CVEs
Other vulnerabilities of type CWE-79
Loading…
Monitor your products
Get automatic alerts for every new CVE affecting your equipment.