Release date:
Updated on:
Affected Systems:
Fortinet FortiMail 4.3.4
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-1471
The FortiMail device is a communication security platform.
In versions earlier than Fortinet FortiMail 4.3.4 on the FortiMail Identity-Based Encryption (IBE) device, multiple cross-site scripting vulnerabilities exist in admin/FEAdmin.html, remote attackers can inject arbitrary Web scripts or HTML through the "Add" Field of the Black List under Antispam Management User Preferences or the User name field of the Personal Black/White List in the AntiSpam area.
<* Source: Benjamin Kunz Mejri
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2013-1471
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Fortinet
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.fortinetfirewall.com/index.php