PSIRT Advisory

XSS vulnerability observed in Log and Report section of FortiGate


An improper neutralization of input vulnerability in the FortiGate may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard.


Unauthorized code execution

Affected Products

FortiGate version 6.2.5 and below.

FortiGate version 6.4.1 and below.


Please upgrade to FortiGate version 6.4.2 or above.

Please upgrade to FortiGate version 6.2.6 or above.


Fortinet is pleased to thank Forster Chiu from CYBERGROOT LTD; Mark Chapman of Chapman Technology Group, Inc; Wenceslas Lejeune and the SOC team from Cheops Technology and Oğuz DOKUMACI from for reporting this vulnerability under responsible disclosure.