Medium severity6.1NVD Advisory· Published Nov 13, 2017· Updated Jun 17, 2026
CVE-2017-7739
CVE-2017-7739
Description
A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim.
Affected products
20cpe:2.3:o:fortinet:fortios:5.2.0:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:o:fortinet:fortios:5.2.0:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.1:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.10:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.11:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.2:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.3:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.4:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.5:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.6:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.7:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.8:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.9:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.0:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.1:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.2:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.3:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.4:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.5:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.6.0:*:*:*:*:*:*:*
- (no CPE)range: 5.6.0
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/101679nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039741nvdThird Party AdvisoryVDB Entry
- fortiguard.com/advisory/FG-IR-17-168nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.