#VU9404 Stored cross-site scripting (XSS) in FortiWeb - CVE-2017-7736
Published: November 22, 2017 / Updated: November 23, 2017
FortiWeb
Fortinet, Inc
Description
Vulnerability allows a remote attacker to perform XSS attacks.
The vulnerability is caused by an input validation error in Fortinet FortiWeb webUI Certificate View page. A remote authenticated attacker can execute arbitrary HTML and script code in victim's browser via special specially crafted malicious certificate import.