FortiWLM - stored cross-site scripting in hotspot profile controller


An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in FortiWLM may allow an authenticated attacker to perform a stored cross site scripting attack (XSS) via storing malicious payloads and trigger the attack on victim's client via various endpoints.

Affected Products

FortiWLM version 8.6.1 and below.
FortiWLM 8.2 all versions
FortiWLM 8.3 all versions
FortiWLM 8.4 all versions
FortiWLM 8.5 all versions


Upgrade to FortiWLM version 8.6.2 or above.


Internally discovered and reported by Mattia Fecit of Fortinet Product Security Team.