CVE-2012-0941: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fieldssortedopt parameter to (4) user/auth/list or (5) endpointcompliance/appdetect/predefinedsiglist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0941?
CVE-2012-0941 is classified as a moderate severity vulnerability due to the potential for remote attackers to exploit multiple cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2012-0941?
To mitigate CVE-2012-0941, upgrade to FortiOS version 4.3.6 or later, which resolves the identified XSS vulnerabilities.
What devices are affected by CVE-2012-0941?
CVE-2012-0941 affects Fortinet FortiGate UTM WAF appliances running FortiOS versions prior to 4.3.6.
What types of attacks can be performed using CVE-2012-0941?
CVE-2012-0941 allows remote attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or session hijacking.
Is CVE-2012-0941 still a risk today?
While CVE-2012-0941 has been patched, systems still running unupdated versions of FortiOS remain vulnerable and should be upgraded immediately.