FortiOS -- XSS vulnerability observed in External Connectors Of Security Fabric

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors.

Affected Products

FortiOS verion 7.2.0.
FortiOS version 6.4.0 through 6.4.9
FortiOS version 7.0.0 through 7.0.5
FortiProxy version 7.0.0 through 7.0.4
FortiProxy version 2.0.0 through 2.0.8
 

Solutions

Please upgrade to FortiOS version 6.4.10 or above.
Please upgrade to FortiOS version 7.0.6 or above.
Please upgrade to FortiOS version 7.2.1 or above.
Please upgrade to FortiProxy version 7.2.0 or above
Please upgrade to FortiProxy version 7.0.5 or above

 

 

Acknowledgement

Fortinet is pleased to thank Massimiliano Ferraresi, Massimiliano Brolli and TIM Security Red Team Research from TIM for reporting this vulnerability under responsible disclosure.