The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published: 2016-04-08T14:00:00.000Z
Updated: 2024-09-16T19:46:15.797Z
Reserved: 2016-04-08T00:00:00.000Z
Link: CVE-2016-3978
No data.
Status : Modified
Published: 2016-04-08T14:59:07.913
Modified: 2026-06-17T00:46:40.273
Link: CVE-2016-3978
No data.
ReportizFlow