CVE-2015-3626: XSS
Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers to inject arbitrary web script or HTML via a crafted hostname.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3626?
CVE-2015-3626 is considered a medium severity vulnerability due to its potential for remote exploitation via cross-site scripting.
How do I fix CVE-2015-3626?
To fix CVE-2015-3626, upgrade FortiOS to version 5.2.4 or later where the vulnerability is mitigated.
What type of attack can exploit CVE-2015-3626?
CVE-2015-3626 can be exploited through cross-site scripting attacks by injecting arbitrary scripts via crafted hostnames.
Which devices are affected by CVE-2015-3626?
CVE-2015-3626 affects FortiGate devices running FortiOS versions earlier than 5.2.4.
Is there a workaround for CVE-2015-3626?
There is no official workaround for CVE-2015-3626, so upgrading to a patched version is recommended.