CVE-2017-3129
MEDIUMFortiWeb <= 5.7.1 - Cross-Site Scripting via Site Publisher POST Parameter
Title source: llmDescription
A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker to execute unauthorized code or commands via an improperly sanitized POST parameter in the FortiWeb Site Publisher feature.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-17-076
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/98382
Scores
CVSS v3
6.1
EPSS
0.0027
EPSS Percentile
49.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
fortinet/fortiweb
< 5.7.1
Fortinet, Inc./Fortinet FortiWeb
FortiWeb versions 5.7.1 and below
Published
May 27, 2017
Tracked Since
Feb 18, 2026