PT-2014-2006 · Fortinet · Fortios
William Costa
·
Published
2014-02-04
·
Updated
2014-02-12
·
CVE-2013-7182
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 5.0.5
Description
The issue is caused by insufficient protection of the web page structure in the FortiOS operating system, specifically in the firewall/schedule/recurrdlg component. This allows a remote attacker to inject arbitrary JavaScript or HTML code through the
mkey parameter, resulting in a cross-site scripting (XSS) vulnerability.Recommendations
For FortiOS version 5.0.5, consider restricting access to the vulnerable
firewall/schedule/recurrdlg component until a patch is available. As a temporary workaround, avoid using the mkey parameter in the affected web interface to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios