383
VMScore

CVE-2018-9186

Published: 31/05/2018 Updated: 22/04/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to prior to 5.3.0 "CSRF validation failure" page allows malicious user to execute unauthorized script code via inject malicious scripts in HTTP referer header.

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortiauthenticator