CVE-2017-3125
12.04.2017, 15:59
An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming the victim is social engineered into clicking an URL crafted by the attacker.
Vendor | Product | Version |
---|---|---|
fortinet | fortimail | 5.0 |
fortinet | fortimail | 5.0.5 |
fortinet | fortimail | 5.0.6 |
fortinet | fortimail | 5.0.7 |
fortinet | fortimail | 5.0.8 |
fortinet | fortimail | 5.0.9 |
fortinet | fortimail | 5.0.10 |
fortinet | fortimail | 5.1 |
fortinet | fortimail | 5.1.2 |
fortinet | fortimail | 5.1.3 |
fortinet | fortimail | 5.1.5 |
fortinet | fortimail | 5.1.6 |
fortinet | fortimail | 5.2 |
fortinet | fortimail | 5.2.1 |
fortinet | fortimail | 5.2.2 |
fortinet | fortimail | 5.2.3 |
fortinet | fortimail | 5.2.4 |
fortinet | fortimail | 5.2.5 |
fortinet | fortimail | 5.2.6 |
fortinet | fortimail | 5.2.7 |
fortinet | fortimail | 5.2.8 |
fortinet | fortimail | 5.2.9 |
fortinet | fortimail | 5.3 |
fortinet | fortimail | 5.3.1 |
fortinet | fortimail | 5.3.2 |
fortinet | fortimail | 5.3.3 |
fortinet | fortimail | 5.3.4 |
fortinet | fortimail | 5.3.5 |
fortinet | fortimail | 5.3.6 |
fortinet | fortimail | 5.3.7 |
fortinet | fortimail | 5.3.8 |
𝑥
= Vulnerable software versions