XSS flaw in Fortiview/SecurityLogs pages

Summary

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI may allow an authenticated attacker to perform an XSS attack via crafted HTTP or HTTPs requests.

Version Affected Solution
FortiADC 7.6 Not affected Not Applicable
FortiADC 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiADC 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiADC 7.1 7.1.0 through 7.1.3 Upgrade to 7.1.4 or above
FortiADC 7.0 7.0 all versions Migrate to a fixed release
FortiADC 6.2 6.2 all versions Migrate to a fixed release
FortiADC 6.1 6.1 all versions Migrate to a fixed release
FortiADC 6.0 6.0 all versions Migrate to a fixed release
FortiADC 5.4 5.4 all versions Migrate to a fixed release
FortiADC 5.3 5.3 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Ming Xie from FortiADC development team.

Timeline

2025-03-11: Initial publication