← Back

CVE-2015-3615

nvd nist
Published: Aug 11, 2017Modified: May 13, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack.

Affected (10)

1 product
Fortimanager Firmware
Configuration A
10 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Fortinet
Version 5.0.10
Version 5.0.3
Version 5.0.4
Version 5.0.5
Version 5.0.6
Version 5.0.7
Version 5.0.8
Version 5.0.9
Version 5.2.0
Version 5.2.1
Running on/withPlatform Versions
Fortinet
Fortimanager 2000e
All versions
Fortinet
Fortimanager 200d
All versions
Fortinet
Fortimanager 3000f
All versions
Fortinet
Fortimanager 300e
All versions
Fortinet
Fortimanager 3900e
All versions
Fortinet
Fortimanager 400e
All versions

References (6)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.