CVE-2015-3615: XSS
Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3615?
CVE-2015-3615 has a high severity rating due to its potential for allowing privilege escalation and cross-site scripting (XSS) attacks.
How do I fix CVE-2015-3615?
To fix CVE-2015-3615, you should update the Fortinet FortiManager firmware to version 5.0.11 or 5.2.2 or later.
What software versions are affected by CVE-2015-3615?
CVE-2015-3615 affects Fortinet FortiManager firmware versions 5.0.x up to 5.0.10 and 5.2.x up to 5.2.1.
Who can exploit CVE-2015-3615?
CVE-2015-3615 can be exploited by remote authenticated users, which indicates that user authentication is required to perform the attack.
What type of vulnerability is CVE-2015-3615?
CVE-2015-3615 is classified as a cross-site scripting (XSS) vulnerability that allows for arbitrary web script or HTML injection.