2 results (0.003 seconds)

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature. Una vulnerabilidad de Cross-Site Scripting (XSS) en Fortinet FortiManager 6.0.0, 5.6.4 y anteriores y FortiAnalyzer 6.0.0, 5.6.4 y anteriores permite inyectar código JavaScript y etiquetas HTML mediante el valor CN de los certificados CA y CRL mediante la característica de importación de certificados CA y CRL. • http://www.securitytracker.com/id/1041246 http://www.securitytracker.com/id/1041247 https://fortiguard.com/advisory/FG-IR-17-305 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 6EXPL: 0

An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter. Una vulnerabilidad de Redireccionamiento Abierto en FortiAnalyzer versiones desde 5.4.0 hasta 5.4.2 y FortiManager versiones desde 5.4.0 hasta 5.4.2 de Fortinet, permite a un atacante ejecutar código o comandos no autorizados por medio del parámetro next. • http://www.securityfocus.com/bid/98557 http://www.securitytracker.com/id/1038539 http://www.securitytracker.com/id/1038540 https://fortiguard.com/psirt/FG-IR-17-014 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •