CVE-2016-3195: XSS
Cross-site scripting (XSS) vulnerability in the Web-UI in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3195?
CVE-2016-3195 is categorized as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2016-3195?
To mitigate CVE-2016-3195, update Fortinet FortiManager and FortiAnalyzer firmware to versions 5.0.12, 5.2.6 or later.
Which versions are affected by CVE-2016-3195?
CVE-2016-3195 affects FortiManager versions 5.x before 5.0.12 and 5.2.x before 5.2.6, as well as FortiAnalyzer versions 5.x before 5.0.13 and 5.2.x before 5.2.6.
What are the potential impacts of CVE-2016-3195?
An attacker exploiting CVE-2016-3195 could inject arbitrary web scripts or HTML into the Web-UI of vulnerable FortiManager and FortiAnalyzer devices.
Is there a workaround for CVE-2016-3195?
While the recommended solution is to update the software, users can also limit access to the Web-UI to trusted networks as an interim workaround.