CVE-2015-1451: XSS
Published Feb 2, 2015
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.
Affected Software
1 affected component
Fortinet FortiOS=5.0.7
Event History
Feb 2, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1451?
CVE-2015-1451 is considered a medium severity vulnerability.
2
How do I fix CVE-2015-1451?
To remediate CVE-2015-1451, upgrade FortiOS to a patched version beyond 5.0.7.
3
Who is affected by CVE-2015-1451?
CVE-2015-1451 affects remote authenticated users of Fortinet FortiOS 5.0 Patch 7 build 4457.
4
What type of vulnerability is CVE-2015-1451?
CVE-2015-1451 is characterized as a cross-site scripting (XSS) vulnerability.
5
What can attackers achieve with CVE-2015-1451?
Attackers can inject arbitrary web scripts or HTML into the Fortinet FortiOS affected system.