VYPR
Unrated severityNVD Advisory· Published Mar 4, 2015· Updated May 6, 2026

CVE-2014-8617

CVE-2014-8617

Description

Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMail before 4.3.9, 5.0.x before 5.0.8, 5.1.x before 5.1.5, and 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via the release parameter to module/releasecontrol.

Affected products

17
  • Fortinet/Fortimail17 versions
    cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*+ 16 more
    • cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*range: <=4.3.8
    • cpe:2.3:a:fortinet:fortimail:5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortimail:5.2.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.