First published: Fri Apr 08 2016(Updated: )
The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | =5.0.0 | |
Fortinet FortiOS | =5.0.1 | |
Fortinet FortiOS | =5.0.2 | |
Fortinet FortiOS | =5.0.3 | |
Fortinet FortiOS | =5.0.4 | |
Fortinet FortiOS | =5.0.5 | |
Fortinet FortiOS | =5.0.6 | |
Fortinet FortiOS | =5.0.7 | |
Fortinet FortiOS | =5.0.8 | |
Fortinet FortiOS | =5.0.9 | |
Fortinet FortiOS | =5.0.10 | |
Fortinet FortiOS | =5.0.11 | |
Fortinet FortiOS | =5.0.12 | |
Fortinet FortiOS | =5.2.0 | |
Fortinet FortiOS | =5.2.1 | |
Fortinet FortiOS | =5.2.2 | |
Fortinet FortiOS | =5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.