CVE-2017-7733: XSS
A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7733?
CVE-2017-7733 is considered a high-severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2017-7733?
To fix CVE-2017-7733, upgrade FortiOS to version 5.4.6 or later or to any version in the 5.6 series that is not vulnerable.
What impact does CVE-2017-7733 have on my system?
CVE-2017-7733 allows attackers to execute arbitrary JavaScript code on users' browsers, potentially leading to data theft or session hijacking.
Which versions of FortiOS are affected by CVE-2017-7733?
CVE-2017-7733 affects Fortinet FortiOS versions 5.4.0 to 5.4.5 and version 5.6.0.
Who is vulnerable to CVE-2017-7733?
Any user accessing the vulnerable versions of FortiOS via the web UI is at risk of exploitation due to CVE-2017-7733.