XSS vulnerability in HTML generated attack report files

Summary

An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface may allow an unauthenticated and remote attacker to perform a reflected cross site scripting attack (XSS) via injecting malicious payload in log entries used to build report.

Version Affected Solution
FortiWeb 7.2 Not affected Not Applicable
FortiWeb 7.0 7.0.0 through 7.0.3 Upgrade to 7.0.4 or above
FortiWeb 6.4 6.4 all versions Migrate to a fixed release
FortiWeb 6.3 6.3.0 through 6.3.21 Upgrade to 6.3.22 or above
FortiWeb 6.2 6.2 all versions Migrate to a fixed release
FortiWeb 6.1 6.1 all versions Migrate to a fixed release
FortiWeb 6.0 6.0 all versions Migrate to a fixed release

Timeline

2023-04-11: Initial publication