CVE-2017-3129

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
27/05/2017
Last modified:
20/04/2025

Description

A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker to execute unauthorized code or commands via an improperly sanitized POST parameter in the FortiWeb Site Publisher feature.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 5.7.1 (including)