HTML Content Injection

Summary

An Improper Neutralization of Script-Related HTML Tags in a Web Page vulnerability [CWE-80] may allow a remote authenticated attacker with admin privileges to cause unvalidated content being presented to users.

Version Affected Solution
FortiPortal 7.4 Not affected Not Applicable
FortiPortal 7.2 Not affected Not Applicable
FortiPortal 7.0 Not affected Not Applicable
FortiPortal 6.0 6.0.0 through 6.0.14 Upgrade to 6.0.15 or above

Acknowledgement

Fortinet is pleased to thank One NZ (Vodafone New Zealand) for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication