Log Pollution via login page

Summary

An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiManager and FortiAnalyzer may allow an unauthenticated remote attacker to pollute the logs via crafted login requests.

Version Affected Solution
FortiAnalyzer 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiAnalyzer 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.8 Upgrade to 7.2.9 or above
FortiAnalyzer 7.0 7.0.0 through 7.0.13 Upgrade to 7.0.14 or above
FortiAnalyzer 6.4 Not affected Not Applicable
FortiManager 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiManager 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiManager 7.2 7.2.0 through 7.2.8 Upgrade to 7.2.9 or above
FortiManager 7.0 7.0.0 through 7.0.13 Upgrade to 7.0.14 or above
FortiManager 6.4 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Alexandre Labb from A1 Digital International for reporting this vulnerability under responsible disclosure.

Timeline

2025-04-08: Initial publication