ZeroHour

CVE-2017-3129

CVSS 3.0
6.1 medium
EPSS
<1%p52
Published
()
Modified
Description

A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker to execute unauthorized code or commands via an improperly sanitized POST parameter in the FortiWeb Site Publisher feature.

Vendors
fortinet
Products
fortiweb
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.