First published: Fri May 26 2017(Updated: )
A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPortal | <=4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7339 has a high severity rating due to its potential to allow unauthorized code execution.
To fix CVE-2017-7339, upgrade FortiPortal to version 4.0.1 or later.
CVE-2017-7339 affects Fortinet FortiPortal versions 4.0.0 and below.
CVE-2017-7339 is classified as a Cross-Site Scripting (XSS) vulnerability.
CVE-2017-7339 involves the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality.