#VU40903 Cross-site scripting in FortiAuthenticator - CVE-2015-1459
Published: February 3, 2015 / Updated: February 14, 2023
FortiAuthenticator
Fortinet, Inc
Description
Vulnerability allows a remote attacker to perform XSS attacks.
The vulnerability is caused by an input validation error in Fortinet FortiAuthenticator 3.0.0 when processing operation parameter to cert/scep/. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
External links
- http://packetstormsecurity.com/files/130156/Fortinet-FortiAuthenticator-XSS-Disclosure-Bypass.html
- http://secunia.com/advisories/62836
- http://www.fortiguard.com/advisory/FG-IR-15-003/
- http://www.security-assessment.com/files/documents/advisory/Fortinet_FortiAuthenticator_Multiple_Vulnerabilities.pdf
- http://www.securityfocus.com/bid/72378
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100561