CVE-2017-7340

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-17-114 Third Party Advisory
https://fortiguard.com/psirt/FG-IR-17-114 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:31

Type Values Removed Values Added
References () https://fortiguard.com/psirt/FG-IR-17-114 - Third Party Advisory () https://fortiguard.com/psirt/FG-IR-17-114 - Third Party Advisory

Information

Published : 2019-03-25 21:29

Updated : 2024-11-21 03:31


NVD link : CVE-2017-7340

Mitre link : CVE-2017-7340

CVE.ORG link : CVE-2017-7340


JSON object : View

Products Affected

fortinet

  • fortiportal
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')