CVE-2015-3612: XSS
Published Feb 4, 2020
·Updated
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.
Affected Software
2 affected components
Fortinet FortiManager>=5.0.0<=5.0.10
Fortinet FortiManager>=5.2.0<=5.2.1
Event History
Feb 4, 2020
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this XSS vulnerability is CVE-2015-3612.
2
What is the severity of CVE-2015-3612?
The severity of CVE-2015-3612 is medium with a CVSS score of 5.4.
3
Which software versions are affected by CVE-2015-3612?
FortiManager versions 5.2.1 and earlier, and 5.0.10 and earlier, are affected by CVE-2015-3612.
4
How does the XSS vulnerability in FortiManager work?
The XSS vulnerability in FortiManager occurs through an unspecified parameter in the FortiWeb auto update service page.
5
Is there a fix available for CVE-2015-3612?
Yes, Fortinet has released a security advisory with a fix for CVE-2015-3612. It is recommended to update to the latest patched version of FortiManager.