CVE-2016-3193: XSS
Cross-site scripting (XSS) vulnerability in the appliance web-application in Fortinet FortiManager 5.x before 5.0.12, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 and FortiAnalyzer 5.x before 5.0.13, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3193?
CVE-2016-3193 has been assigned a medium severity rating due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2016-3193?
To fix CVE-2016-3193, update FortiManager to version 5.0.12 or higher, 5.2.6 or higher, or 5.4.1 or higher, and FortiAnalyzer to the respective patched versions.
Who is affected by CVE-2016-3193?
CVE-2016-3193 affects remote authenticated users of Fortinet FortiManager and FortiAnalyzer versions prior to the specified patched versions.
What is the attack vector for CVE-2016-3193?
The attack vector for CVE-2016-3193 involves remote authenticated users being able to inject arbitrary web script or HTML.
What kind of vulnerability is CVE-2016-3193?
CVE-2016-3193 is classified as a persistent cross-site scripting (XSS) vulnerability.