CVE-2017-7732: XSS
A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized pre-authentication webmail login page allows attacker to inject arbitrary web script or HTML via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7732?
CVE-2017-7732 is categorized as a medium severity reflected Cross-Site Scripting (XSS) vulnerability.
How does CVE-2017-7732 affect Fortinet FortiMail?
CVE-2017-7732 allows attackers to inject arbitrary web scripts or HTML into the pre-authentication webmail login page of affected FortiMail versions.
How do I fix CVE-2017-7732?
To mitigate CVE-2017-7732, Fortinet recommends upgrading to a patched version of FortiMail beyond the vulnerable releases.
Which versions of FortiMail are affected by CVE-2017-7732?
CVE-2017-7732 affects Fortinet FortiMail versions 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9.
What are the symptoms of exploitation of CVE-2017-7732?
Symptoms of exploitation of CVE-2017-7732 may include unexpected behavior on the webmail login page, such as the execution of malicious scripts.