CVE-2018-9186
Summary
| CVE | CVE-2018-9186 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-31 22:29:00 UTC |
| Updated | 2019-04-22 18:32:00 UTC |
| Description | A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Fortiauthenticator | All | All | All | All |
| Application | Fortinet | Fortiauthenticator | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Potential XSS in "CSRF validation failure" page due to lack of referer sanitization | FortiGuard | CONFIRM | fortiguard.com | Vendor Advisory |
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.