Vulnerability Details CVE-2015-3615
Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.1%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2015-3615
-
cpe:2.3:h:fortinet:fortimanager_2000e:-
-
cpe:2.3:h:fortinet:fortimanager_200d:-
-
cpe:2.3:h:fortinet:fortimanager_3000f:-
-
cpe:2.3:h:fortinet:fortimanager_300e:-
-
cpe:2.3:h:fortinet:fortimanager_3900e:-
-
cpe:2.3:h:fortinet:fortimanager_400e:-
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.0.10
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.0.3
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.0.4
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.0.5
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.0.6
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.0.7
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.0.8
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.0.9
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.2.0
-
cpe:2.3:o:fortinet:fortimanager_firmware:5.2.1