CVE-2019-17651: XSS
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedule.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-17651.
What is the severity of CVE-2019-17651?
The severity of CVE-2019-17651 is medium with a CVSS score of 5.4.
Which software versions are affected by CVE-2019-17651?
FortiSIEM version 5.2.5 and below are affected by CVE-2019-17651.
What is the impact of CVE-2019-17651?
CVE-2019-17651 allows a remote authenticated attacker to perform a Stored Cross Site Scripting (XSS) attack by injecting malicious JavaScript code into the description and title parameters of a Device Maintenance Schedule.
Is there a fix available for CVE-2019-17651?
At the moment, there is no information available about a fix for CVE-2019-17651. It is recommended to follow the vendor's security advisory for updates and patches.