CVE-2017-7739: XSS
A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7739?
CVE-2017-7739 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2017-7739?
To fix CVE-2017-7739, update Fortinet FortiOS to a version that addresses the vulnerability, preferably 5.6.1 or later.
What systems are affected by CVE-2017-7739?
CVE-2017-7739 affects Fortinet FortiOS versions 5.2.0 to 5.2.11, 5.4.0 to 5.4.5, and 5.6.0.
Can CVE-2017-7739 be exploited remotely?
Yes, CVE-2017-7739 can be exploited remotely by an unauthenticated attacker sending a specially crafted request.
What are the potential impacts of CVE-2017-7739?
Exploitation of CVE-2017-7739 could allow attackers to inject arbitrary web scripts or HTML into the victim's browser.