CVE-2017-7732
26.10.2017, 13:29
A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized pre-authentication webmail login page allows attacker to inject arbitrary web script or HTML via crafted HTTP requests.
Vendor | Product | Version |
---|---|---|
fortinet | fortimail | 4.1.0 |
fortinet | fortimail | 4.2.0 |
fortinet | fortimail | 4.3.0 |
fortinet | fortimail | 4.3.8 |
fortinet | fortimail | 5.0 |
fortinet | fortimail | 5.0.1 |
fortinet | fortimail | 5.0.2 |
fortinet | fortimail | 5.0.3 |
fortinet | fortimail | 5.0.4 |
fortinet | fortimail | 5.0.5 |
fortinet | fortimail | 5.0.6 |
fortinet | fortimail | 5.0.7 |
fortinet | fortimail | 5.0.8 |
fortinet | fortimail | 5.0.9 |
fortinet | fortimail | 5.0.10 |
fortinet | fortimail | 5.1 |
fortinet | fortimail | 5.2 |
fortinet | fortimail | 5.2.1 |
fortinet | fortimail | 5.2.2 |
fortinet | fortimail | 5.2.3 |
fortinet | fortimail | 5.2.4 |
fortinet | fortimail | 5.2.5 |
fortinet | fortimail | 5.2.6 |
fortinet | fortimail | 5.2.7 |
fortinet | fortimail | 5.2.8 |
fortinet | fortimail | 5.2.9 |
fortinet | fortimail | 5.3 |
fortinet | fortimail | 5.3.1 |
fortinet | fortimail | 5.3.2 |
fortinet | fortimail | 5.3.3 |
fortinet | fortimail | 5.3.4 |
fortinet | fortimail | 5.3.5 |
fortinet | fortimail | 5.3.6 |
fortinet | fortimail | 5.3.7 |
fortinet | fortimail | 5.3.8 |
fortinet | fortimail | 5.3.9 |
𝑥
= Vulnerable software versions