PSIRT Advisory

XSS vulnerability in FortiOS SSLVPN Portal

Summary

An improper neutralization of input during web page generation in the SSL VPN portal of FortiOS may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).

Impact

Unauthorized code execution

Affected Products

FortiOS version 6.2.1 and below. FortiOS version 6.0.8 and below. FortiOS version 5.6.12 and below.

Solutions

Please upgrade to FortiOS version 6.2.2 or above. Please upgrade to FortiOS version 6.0.9 or above. Please upgrade to FortiOS version 5.6.13 or above.

Acknowledgement

Fortinet is pleased to thank Qingtang Zheng from CodeSafe Team of Legendsec at Qi'anXin Group and Choudhary Muhammad Osama for bringing this issue to our attention under responsible disclosure.