Vulnerabilities > Fortinet > Fortimanager > 5.2.1

DATE CVE VULNERABILITY TITLE RISK
2019-05-28 CVE-2018-13375 Cross-site Scripting vulnerability in Fortinet Fortianalyzer and Fortimanager
An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter.
network
fortinet CWE-79
4.3
2019-04-25 CVE-2018-1360 Cleartext Transmission of Sensitive Information vulnerability in Fortinet Fortimanager
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.
network
fortinet CWE-319
4.3
2018-09-05 CVE-2018-1353 Information Exposure vulnerability in Fortinet Fortimanager
An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom.
network
low complexity
fortinet CWE-200
4.0
2018-06-28 CVE-2018-1351 Cross-site Scripting vulnerability in Fortinet Fortimanager
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log.
network
fortinet CWE-79
3.5
2018-06-27 CVE-2018-1355 Open Redirect vulnerability in Fortinet Fortianalyzer and Fortimanager
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature.
network
fortinet CWE-601
5.8
2018-06-27 CVE-2018-1354 Incorrect Permission Assignment for Critical Resource vulnerability in Fortinet Fortianalyzer and Fortimanager
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
network
low complexity
fortinet CWE-732
4.0