CVE-2015-3620
Summary
| CVE | CVE-2015-3620 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-12 19:59:23 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the advanced dataset reports page in Fortinet FortiAnalyzer 5.0.0 through 5.0.10 and 5.2.0 through 5.2.1 and FortiManager 5.0.3 through 5.0.10 and 5.2.0 through 5.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fortinet | Fortianalyzer Firmware | 5.0.0 | All | All | All |
| Operating System | Fortinet | Fortianalyzer Firmware | 5.0.1 | All | All | All |
| Operating System | Fortinet | Fortianalyzer Firmware | 5.0.10 | All | All | All |
| Operating System | Fortinet | Fortianalyzer Firmware | 5.2.0 | All | All | All |
| Operating System | Fortinet | Fortianalyzer Firmware | 5.2.1 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.0.10 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.0.3 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.0.4 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.0.5 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.0.6 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.0.7 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.0.8 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.0.9 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.2.0 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 5.2.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: Fortinet FortiAnalyzer & FortiManager - Client Side Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit, Third Party Advisory, VDB Entry |
| Fortinet FortiManager Input Validation Flaws in SSLVPN Login Page, User Group Menu, VPN Template Menu, and Advanced Dataset Reports Page Permit Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Fortinet FortiAnalyzer / FortiManager Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| FortiGuard.com | Multiple products cross-site scripting vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.fortiguard.com | Vendor Advisory |
| FortiAnalyzer and FortiManager CVE-2015-3620 Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.