First published: Tue Feb 04 2020(Updated: )
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiManager | >=5.0.0<=5.0.10 | |
Fortinet FortiManager | >=5.2.0<=5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this XSS vulnerability is CVE-2015-3612.
The severity of CVE-2015-3612 is medium with a CVSS score of 5.4.
FortiManager versions 5.2.1 and earlier, and 5.0.10 and earlier, are affected by CVE-2015-3612.
The XSS vulnerability in FortiManager occurs through an unspecified parameter in the FortiWeb auto update service page.
Yes, Fortinet has released a security advisory with a fix for CVE-2015-3612. It is recommended to update to the latest patched version of FortiManager.