XSS observed on policy column settings

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal management interface may allow a remote authenticated attacker to perform a stored cross site scripting (XSS) attack via sending request with specially crafted columnindex parameter.

Version Affected Solution
FortiPortal 7.0 Not affected Not Applicable
FortiPortal 6.0 6.0.0 through 6.0.11 Upgrade to 6.0.12 or above
FortiPortal 5.3 5.3 all versions Migrate to a fixed release
FortiPortal 5.2 5.2 all versions Migrate to a fixed release
FortiPortal 5.1 5.1 all versions Migrate to a fixed release
FortiPortal 5.0 5.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Dmitry Bulkot from DEFEND ltd for reporting this vulnerability under responsible disclosure.

Timeline

2023-01-03: Initial publication