Vulnerability Description
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | 5.2.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99098Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038705Third Party AdvisoryVDB Entry
- https://fortiguard.com/advisory/FG-IR-17-127MitigationVendor Advisory
- http://www.securityfocus.com/bid/99098Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038705Third Party AdvisoryVDB Entry
- https://fortiguard.com/advisory/FG-IR-17-127MitigationVendor Advisory
FAQ
What is CVE-2017-7735?
CVE-2017-7735 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while cr...
How severe is CVE-2017-7735?
CVE-2017-7735 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7735?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortios.