Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortimanager  >> 5.4.3  Security Vulnerabilities
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log.
CVSS Score
4.8
EPSS Score
0.001
Published
2018-06-28
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.
CVSS Score
6.1
EPSS Score
0.001
Published
2018-06-27
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
CVSS Score
6.5
EPSS Score
0.001
Published
2018-06-27


Contact Us

Shodan ® - All rights reserved