XSS vulnerability in the Security Profiles comments section in FortiGate Cloud


An improper neutralization of input vulnerability in FortiGate Cloud may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the comments section of the Security Profiles.

Affected Products

FortiGate Cloud Version 20.3 and below.


Fortinet has remediated this issue in FortiGate Cloud version 20.4 and hence the customers do not need to perform any action.


Fortinet is pleased to thank Johnatan Camargo from Itau-Unibanco for reporting this vulnerability under responsible disclosure.