← Back

CVE-2015-7363

nvd nist
Published: Oct 7, 2016Modified: May 6, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrators to inject arbitrary web script or HTML via vectors related to report filters.

Affected (30)

2 products
Fortimanager Firmware
Fortianalyzer Firmware
Configuration A
14 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Fortinet
Version 5.0.0
Version 5.0.10
Version 5.0.11
Version 5.0.1
Version 5.0.2
Version 5.0.3
Version 5.0.4
Version 5.0.5
Version 5.0.6
Version 5.0.7
Version 5.0.8
Version 5.0.9
Version 5.2.0
Version 5.2.1
Running on/withPlatform Versions
Fortinet
Fortimanager
All versions
Configuration B
16 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Fortinet
Version 5.0.0
Version 5.0.10
Version 5.0.11
Version 5.0.12
Version 5.0.1
Version 5.0.2
Version 5.0.3
Version 5.0.4
Version 5.0.5
Version 5.0.6
Version 5.0.7
Version 5.0.8
Version 5.0.9
Version 5.2.0
Version 5.2.1
Version 5.2.2
Running on/withPlatform Versions
Fortinet
Fortianalyzer
All versions

References (8)

Timeline

No history available yet.