CVE-2015-7363: XSS
Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrators to inject arbitrary web script or HTML via vectors related to report filters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7363?
CVE-2015-7363 is considered a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-7363?
To fix CVE-2015-7363, upgrade Fortinet FortiManager to version 5.0.12 or later, or FortiAnalyzer to version 5.0.13 or later.
What versions are affected by CVE-2015-7363?
CVE-2015-7363 affects FortiManager versions prior to 5.0.12 and 5.2.3, as well as FortiAnalyzer versions prior to 5.0.13 and 5.2.3.
What types of attacks can CVE-2015-7363 enable?
CVE-2015-7363 can enable attackers to inject arbitrary web scripts or HTML into the advanced settings page.
Who can exploit CVE-2015-7363?
CVE-2015-7363 can be exploited by remote administrators who have access to the affected FortiManager or FortiAnalyzer systems.