First published: Fri Oct 27 2017(Updated: )
A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | =5.4.0 | |
Fortinet FortiOS | =5.4.1 | |
Fortinet FortiOS | =5.4.2 | |
Fortinet FortiOS | =5.4.3 | |
Fortinet FortiOS | =5.4.4 | |
Fortinet FortiOS | =5.4.5 | |
Fortinet FortiOS | =5.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7733 is considered a high-severity Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2017-7733, upgrade FortiOS to version 5.4.6 or later or to any version in the 5.6 series that is not vulnerable.
CVE-2017-7733 allows attackers to execute arbitrary JavaScript code on users' browsers, potentially leading to data theft or session hijacking.
CVE-2017-7733 affects Fortinet FortiOS versions 5.4.0 to 5.4.5 and version 5.6.0.
Any user accessing the vulnerable versions of FortiOS via the web UI is at risk of exploitation due to CVE-2017-7733.