CVE-2016-3196: XSS
Cross-site scripting (XSS) vulnerability in Fortinet FortiAnalyzer 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an image uploaded in the report section.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3196?
CVE-2016-3196 has a medium severity rating due to the potential for cross-site scripting attacks.
How do I fix CVE-2016-3196?
To fix CVE-2016-3196, upgrade Fortinet FortiAnalyzer to version 5.0.12 or later and FortiManager to version 5.0.12 or later.
What versions are affected by CVE-2016-3196?
Affected versions are Fortinet FortiAnalyzer 5.x before 5.0.12 and 5.2.x before 5.2.6, as well as FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6.
Who can exploit CVE-2016-3196?
CVE-2016-3196 can be exploited by remote authenticated users who can upload images in the report section.
What type of vulnerability is CVE-2016-3196?
CVE-2016-3196 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts or HTML.