{"api_version":"1","generated_at":"2026-07-23T08:08:38+00:00","cve":"CVE-2017-7339","urls":{"html":"https://cve.report/CVE-2017-7339","api":"https://cve.report/api/cve/CVE-2017-7339.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7339","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7339"},"summary":{"title":"CVE-2017-7339","description":"A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality.","state":"PUBLISHED","assigner":"fortinet","published_at":"2017-05-27 00:29:01","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-79","Execution of unauthorized code or commands"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://fortiguard.com/psirt/FG-IR-17-114","name":"https://fortiguard.com/psirt/FG-IR-17-114","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"FortiPortal Multiple Vulnerabilities | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7339","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7339","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Fortinet, Inc.","product":"Fortinet FortiPortal","version":"affected FortiPortal versions 4.0.0 and below","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7339","vulnerable":"1","versionEndIncluding":"4.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"fortiportal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T15:56:36.461Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://fortiguard.com/psirt/FG-IR-17-114"}],"title":"CVE Program Container"},{"metrics":[{"other":{"content":{"id":"CVE-2017-7339","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-10-23T14:00:49.246157Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-10-25T14:13:38.427Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"Fortinet FortiPortal","vendor":"Fortinet, Inc.","versions":[{"status":"affected","version":"FortiPortal versions 4.0.0 and below"}]}],"datePublic":"2017-05-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality."}],"problemTypes":[{"descriptions":[{"description":"Execution of unauthorized code or commands","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-05-26T21:57:01.000Z","orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://fortiguard.com/psirt/FG-IR-17-114"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@fortinet.com","ID":"CVE-2017-7339","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Fortinet FortiPortal","version":{"version_data":[{"version_value":"FortiPortal versions 4.0.0 and below"}]}}]},"vendor_name":"Fortinet, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Execution of unauthorized code or commands"}]}]},"references":{"reference_data":[{"name":"https://fortiguard.com/psirt/FG-IR-17-114","refsource":"CONFIRM","url":"https://fortiguard.com/psirt/FG-IR-17-114"}]}}}},"cveMetadata":{"assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","assignerShortName":"fortinet","cveId":"CVE-2017-7339","datePublished":"2017-05-26T22:00:00.000Z","dateReserved":"2017-03-30T00:00:00.000Z","dateUpdated":"2024-10-25T14:13:38.427Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-05-27 00:29:01","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-79","Execution of unauthorized code or commands"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*","versionEndIncluding":"4.0.0","matchCriteriaId":"F12C46D5-F018-4114-86A5-AF643CFA348C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7339","Ordinal":"1","Title":"CVE-2017-7339","CVE":"CVE-2017-7339","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7339","Ordinal":"1","NoteData":"A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality.","Type":"Description","Title":"CVE-2017-7339"},{"CveYear":"2017","CveId":"7339","Ordinal":"2","NoteData":"2017-05-26","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7339","Ordinal":"3","NoteData":"2017-05-26","Type":"Other","Title":"Modified"}]}}}