Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-1471


Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User Preferences or (2) the User name field for the Personal Black/White List in the AntiSpam section.


Published

2013-02-04T19:55:01.833

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortimail ≤ 4.0 Yes
Application fortinet fortimail 3.0 Yes
Application fortinet fortimail 3.0 Yes
Application fortinet fortimail 3.0 Yes
Application fortinet fortimail 3.0 Yes
Application fortinet fortimail 4.0 Yes
Application fortinet fortimail 4.0 Yes
Application fortinet fortimail 4.0 Yes
Hardware fortinet fortimail-2000b - No
Hardware fortinet fortimail-200d - No
Hardware fortinet fortimail-400c - No
Hardware fortinet fortimail-5002b - No
Hardware fortinet fortimail-vm2000 - No

References