CVE-2015-8038
FortiManager < 5.2.3 - Cross-Site Scripting via sharedjobmanager or SOMServiceObjDialog
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-8038. PoCs published by hyp3rlinx.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in FortiManager v5.2.2 and v5.2.3, including reflected and stored XSS via the 'vdom' parameter and a textarea field. The PoC includes URLs with injected JavaScript payloads to trigger alerts and disclose cookies.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sharedjobmanager or (2) SOMServiceObjDialog.
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in FortiManager v5.2.2 and v5.2.3, including reflected and stored XSS via the 'vdom' parameter and a textarea field. The PoC includes URLs with injected JavaScript payloads to trigger alerts and disclose cookies.