First published: Tue Aug 11 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers to inject arbitrary web script or HTML via a crafted hostname.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | <=5.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3626 is considered a medium severity vulnerability due to its potential for remote exploitation via cross-site scripting.
To fix CVE-2015-3626, upgrade FortiOS to version 5.2.4 or later where the vulnerability is mitigated.
CVE-2015-3626 can be exploited through cross-site scripting attacks by injecting arbitrary scripts via crafted hostnames.
CVE-2015-3626 affects FortiGate devices running FortiOS versions earlier than 5.2.4.
There is no official workaround for CVE-2015-3626, so upgrading to a patched version is recommended.