Description
Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User Preferences or (2) the User name field for the Personal Black/White List in the AntiSpam section.
Published: 2013-02-04
Score: 4.3 Medium
EPSS: 4.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2013-1507 Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User Preferences or (2) the User name field for the Personal Black/White List in the AntiSpam section.
History

No history.

Subscriptions

Fortinet Fortimail Fortimail-2000b Fortimail-200d Fortimail-400c Fortimail-5002b Fortimail-vm2000
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T20:22:55.684Z

Reserved: 2013-01-30T00:00:00.000Z

Link: CVE-2013-1471

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-02-04T19:55:01.833

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-1471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses