First published: Tue May 12 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) user group or (2) vpn template menus.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | =5.2.0 | |
Fortinet FortiOS IPS Engine | =5.2.1 | |
Fortinet FortiOS IPS Engine | =5.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8616 is classified as a moderate severity vulnerability.
To fix CVE-2014-8616, upgrade FortiOS to version 5.2.3 or later.
CVE-2014-8616 allows attackers to execute arbitrary web scripts or HTML through cross-site scripting (XSS).
FortiOS versions 5.2.0, 5.2.1, and 5.2.2 are affected by CVE-2014-8616.
CVE-2014-8616 affects the user group and VPN template menus in FortiOS.