PT-2017-3710 · Fortinet · Fortios

Publicado

2017-11-03

·

Atualizado

2017-11-29

·

CVE-2017-7739

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: FortiOS versions 5.2.0 through 5.2.11 FortiOS versions 5.4.0 through 5.4.5 FortiOS version 5.6.0
Description: The issue is caused by insufficient protection of the web page structure, allowing a remote attacker to inject arbitrary JavaScript or HTML code using a specially crafted URI. This is a reflected Cross-site Scripting (XSS) vulnerability in the web proxy disclaimer response web pages. An unauthenticated attacker can exploit this by sending a maliciously crafted URL to the victim, resulting in the execution of arbitrary JavaScript code in the context of the victim's browser.
Recommendations: For FortiOS versions 5.2.0 through 5.2.11, update to a version that includes the fix for this issue. For FortiOS versions 5.4.0 through 5.4.5, update to a version that includes the fix for this issue. For FortiOS version 5.6.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the web proxy disclaimer response web pages until a patch is available. Avoid using specially crafted URLs that could exploit this issue until the vulnerability is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01280
CVE-2017-7739

Produtos afetados

Fortios