CVE-2016-4969: XSS
Published Sep 21, 2016
·Updated
Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the IP parameter to script/statistics/getconn.php.
Affected Software
1 affected component
Fortinet FortiWan<=4.2.4
Event History
Sep 21, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4969?
CVE-2016-4969 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2016-4969?
The issue can be resolved by upgrading Fortinet FortiWan to version 4.2.5 or later.
3
What systems are affected by CVE-2016-4969?
CVE-2016-4969 affects Fortinet FortiWan versions prior to 4.2.5.
4
What type of attack can occur with CVE-2016-4969?
CVE-2016-4969 allows remote attackers to inject arbitrary web scripts or HTML through an XSS vulnerability.
5
Is CVE-2016-4969 easy to exploit?
Exploiting CVE-2016-4969 requires access to the affected web interface, which can make it easier for attackers to execute malicious scripts.