PSIRT Advisories
XSS vulnerability in FortiWeb
Summary
An improper neutralization of input during web page generation in FortiWeb GUI interface may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.Affected Products
FortiWeb versions 6.3.13 and below.FortiWeb versions 6.2.4 and below.
Solutions
Please upgrade to FortiWeb versions 6.3.14 or above.Please upgrade to FortiWeb versions 6.2.5 or above.