CVE-2015-1451

FortiOS 5.0 Patch 7 build 4457 - Authenticated Cross-Site Scripting via WTP Name or Active Software Version Field

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.

References (5)

Core 5
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/125
Vendor Advisory x_refsource_confirm
http://www.fortiguard.com/advisory/FG-IR-15-002/
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61661
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72383

Scores

EPSS 0.0024
EPSS Percentile 47.0%

Details

CWE
CWE-79
Status published
Products (1)
fortinet/fortios 5.0.7
Published Feb 02, 2015
Tracked Since Feb 18, 2026