XSS vulnerability in FortiOS SSLVPN Portal
Fortinet PSIRT Advisories
Fortinet PSIRT Contact:
Website: https://fortiguard.fortinet.com/faq/psirt-contact
FG-IR-19-223
Final
1
1
2020-09-16T00:00:00
Current version
2020-09-16T00:00:00
2020-09-16T00:00:00
An improper neutralization of input during web page generation in the SSL VPN portal of FortiOS may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).
Unauthorized code execution
FortiOS version 6.2.1 and below. FortiOS version 6.0.8 and below. FortiOS version 5.6.12 and below.
Please upgrade to FortiOS version 6.2.2 or above. Please upgrade to FortiOS version 6.0.9 or above. Please upgrade to FortiOS version 5.6.13 or above.
Fortinet is pleased to thank Qingtang Zheng from CodeSafe Team of Legendsec at Qi'anXin Group and Choudhary Muhammad Osama from BankIslami Pakistan Limited for bringing this issue to our attention under responsible disclosure.
FortiOS 6.2.1
FortiOS 6.2.0
FortiOS 6.0.8
FortiOS 6.0.7
FortiOS 6.0.6
FortiOS 6.0.5
FortiOS 6.0.4
FortiOS 6.0.3
FortiOS 6.0.2
FortiOS 6.0.1
FortiOS 6.0.0
FortiOS 5.6.12
XSS vulnerability in FortiOS SSLVPN Portal
CVE-2019-15706
FortiOS-6.2.1
FortiOS-6.2.0
FortiOS-6.0.8
FortiOS-6.0.7
FortiOS-6.0.6
FortiOS-6.0.5
FortiOS-6.0.4
FortiOS-6.0.3
FortiOS-6.0.2
FortiOS-6.0.1
FortiOS-6.0.0
FortiOS-5.6.12
https://fortiguard.fortinet.com/psirt/FG-IR-19-223
XSS vulnerability in FortiOS SSLVPN Portal
Reference>