CVE-2014-1458: XSS
Published Feb 4, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Fortinet FortiWeb<=5.0.3
Event History
Feb 4, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·09:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1458?
CVE-2014-1458 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-1458?
To fix CVE-2014-1458, you should upgrade FortiWeb to a version later than 5.0.3.
3
Who is impacted by CVE-2014-1458?
CVE-2014-1458 impacts remote authenticated administrators using FortiWeb versions 5.0.3 and earlier.
4
What type of vulnerability is CVE-2014-1458?
CVE-2014-1458 is classified as a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2014-1458?
Attackers can exploit CVE-2014-1458 to inject arbitrary web scripts or HTML into the web administration interface.