A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038705 | third party advisory vdb entry |
https://fortiguard.com/advisory/FG-IR-17-127 | mitigation vendor advisory |
http://www.securityfocus.com/bid/99098 | third party advisory vdb entry |