CVE-2016-3194: XSS
Cross-site scripting (XSS) vulnerability in the address added page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3194?
CVE-2016-3194 is classified as a high severity cross-site scripting (XSS) vulnerability.
Which versions are affected by CVE-2016-3194?
CVE-2016-3194 affects Fortinet FortiManager versions 5.x before 5.0.12 and 5.2.x before 5.2.6, as well as FortiAnalyzer versions 5.x before 5.0.13 and 5.2.x before 5.2.6.
How do I fix CVE-2016-3194?
To fix CVE-2016-3194, upgrade FortiManager to version 5.0.12 or later and FortiAnalyzer to version 5.0.13 or later.
What type of attack can exploit CVE-2016-3194?
CVE-2016-3194 can be exploited by remote attackers to inject arbitrary web scripts or HTML, potentially affecting users' interactions with the application.
Is there a patch available for CVE-2016-3194?
Yes, patches are available in the form of firmware updates for the affected Fortinet products.