← Back

CVE-2013-1471

nvd nist
Published: Feb 4, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User Preferences or (2) the User name field for the Personal Black/White List in the AntiSpam section.

Affected (8)

Products: Fortinet: Fortimail
1 product
Fortimail
Configuration A
8 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Fortinet
Up to 4.0
Version 3.0 mr2
Version 3.0 mr3
Version 3.0 mr4
Version 3.0 mr5
Version 4.0
Version 4.0 mr1
Version 4.0 mr2
Running on/withPlatform Versions
Fortinet
Fortimail 2000b
All versions
Fortinet
Fortimail 200d
All versions
Fortinet
Fortimail 400c
All versions
Fortinet
Fortimail 5002b
All versions
Fortinet
Fortimail Vm2000
All versions

References (6)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.