First published: Mon Nov 02 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sharedjobmanager or (2) SOMServiceObjDialog.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet Fortimanager Firmware | <=5.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8038 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts.
To fix CVE-2015-8038, upgrade Fortinet FortiManager to version 5.2.4 or later.
CVE-2015-8038 can be exploited to perform cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
Fortinet FortiManager versions prior to 5.2.4, specifically up to 5.2.3, are vulnerable to CVE-2015-8038.
There are no official workarounds for CVE-2015-8038; the recommended action is to upgrade to a secure version.