CVE-2017-7735

medium

Description

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.

References

https://fortiguard.com/advisory/FG-IR-17-127

http://www.securitytracker.com/id/1038705

http://www.securityfocus.com/bid/99098

Details

Source: Mitre, NVD

Published: 2017-09-12

Updated: 2017-09-15

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium