First published: Tue Jan 28 2020(Updated: )
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedule.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSIEM | <=5.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-17651.
The severity of CVE-2019-17651 is medium with a CVSS score of 5.4.
FortiSIEM version 5.2.5 and below are affected by CVE-2019-17651.
CVE-2019-17651 allows a remote authenticated attacker to perform a Stored Cross Site Scripting (XSS) attack by injecting malicious JavaScript code into the description and title parameters of a Device Maintenance Schedule.
At the moment, there is no information available about a fix for CVE-2019-17651. It is recommended to follow the vendor's security advisory for updates and patches.