CVE-2017-17541
Summary
| CVE | CVE-2017-17541 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-16 20:29:00 UTC |
| Updated | 2018-09-12 19:22:00 UTC |
| Description | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fortinet | Fortianalyzer Firmware | 6.0.0 | All | All | All |
| Operating System | Fortinet | Fortianalyzer Firmware | 6.0.0 | All | All | All |
| Operating System | Fortinet | Fortianalyzer Firmware | All | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 6.0.0 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | 6.0.0 | All | All | All |
| Operating System | Fortinet | Fortimanager Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Stored XSS under CA and CRL certificate view page | FortiGuard | CONFIRM | fortiguard.com | Vendor Advisory |
| Fortinet FortiAnalyzer Input Validation Flaw in CA and CRL Certificate View Page Lets Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Fortinet FortiManager Input Validation Flaw in CA and CRL Certificate View Page Lets Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.