CVE-2017-7340

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-17-114 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-03-25 21:29

Updated : 2023-12-10 12:59


NVD link : CVE-2017-7340

Mitre link : CVE-2017-7340

CVE.ORG link : CVE-2017-7340


JSON object : View

Products Affected

fortinet

  • fortiportal
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')