Files
CVEs-PoC/2017/CVE-2017-7735.md
T
2025-09-29 21:09:30 +02:00

18 lines
834 B
Markdown

### [CVE-2017-7735](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7735)
![](https://img.shields.io/static/v1?label=Product&message=Fortinet%20FortiOS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=FortiOS%20versions%205.2.0%20through%205.2.11%2C%20and%205.4.0%20through%205.4.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Execute%20unauthorized%20code%20or%20commands&color=brightgreen)
### Description
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.
### POC
#### Reference
- https://fortiguard.com/advisory/FG-IR-17-127
#### Github
No PoCs found on GitHub currently.