CVE-2017-3131: XSS
Published Sep 12, 2017
·Updated
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.
Affected Software
6 affected components
Fortinet FortiOS=5.4.0
Fortinet FortiOS=5.4.1
Fortinet FortiOS=5.4.2
Fortinet FortiOS=5.4.3
Fortinet FortiOS=5.4.4
Fortinet FortiOS=5.6.0
Event History
Sep 12, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3131?
CVE-2017-3131 is classified as a medium severity Cross-Site Scripting vulnerability.
2
How do I fix CVE-2017-3131?
To fix CVE-2017-3131, update Fortinet FortiOS to a version beyond 5.4.4 or 5.6.0.
3
What versions of FortiOS are affected by CVE-2017-3131?
CVE-2017-3131 affects FortiOS versions 5.4.0 through 5.4.4, and 5.6.0.
4
What kind of attacks can exploit CVE-2017-3131?
CVE-2017-3131 can be exploited to execute unauthorized code or commands via the filter input in FortiView applications.
5
Is there a workaround for CVE-2017-3131?
There are no official workarounds for CVE-2017-3131; the recommended action is to upgrade to a non-vulnerable version.