Medium severity6.1NVD Advisory· Published Nov 13, 2017· Updated May 13, 2026
CVE-2017-7739
CVE-2017-7739
Description
A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim.
Affected products
20cpe:2.3:o:fortinet:fortios:5.2.0:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:o:fortinet:fortios:5.2.0:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.1:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.10:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.11:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.2:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.3:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.4:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.5:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.6:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.7:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.8:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.9:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.0:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.1:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.2:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.3:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.4:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.5:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.6.0:*:*:*:*:*:*:*
- (no CPE)range: 5.6.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/101679nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039741nvdThird Party AdvisoryVDB Entry
- fortiguard.com/advisory/FG-IR-17-168nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.