First published: Mon Mar 25 2019(Updated: )
A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPortal | <=4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-7340.
The affected software is Fortinet FortiPortal versions 4.0.0 and below.
The severity of CVE-2017-7340 is medium with a CVSS severity value of 6.1.
An attacker can exploit this vulnerability by executing unauthorized code or commands using the applicationSearch parameter in the FortiView functionality.
To fix this vulnerability, it is recommended to update Fortinet FortiPortal to a version above 4.0.0.