CVE-2015-8037
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SOMVpnSSLPortalDialog or (2) FGDMngUpdHistory.
- Affected products
- Fortimanager
- Fortinet Fortimanager Firmware
- ≤ 5.2.3
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 2.8% (85th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2015-11-02
CVE-2015-8037 at NVD
2 known exploits for CVE-2015-8037
Proof-of-concept code and exploit modules indexed by Sploitus