XSS vulnerability in the Description Area of the Admin Profile
Fortinet PSIRT Advisories
Fortinet PSIRT Contact:
Website: https://fortiguard.fortinet.com/faq/psirt-contact
FG-IR-20-003
Final
1
1
2020-06-03T00:00:00
Current version
2020-06-03T00:00:00
2020-06-03T00:00:00
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.
Unauthorized code execution
FortiAnalyzer version 6.2.3 and below.
Please upgrade to FortiAnalyzer version 6.2.4 or above.Please upgrade to FortiAnalyzer version 6.4.0 or above.
Fortinet is pleased to thank Ali Ardic from Trend Micro for reporting this vulnerability under responsible disclosure.
FortiAnalyzer 6.2.3
FortiAnalyzer 6.2.2
XSS vulnerability in the Description Area of the Admin Profile
CVE-2020-6640
FortiAnalyzer-6.2.3
FortiAnalyzer-6.2.2
4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N/E:F/RL:X/RC:X
https://fortiguard.fortinet.com/psirt/FG-IR-20-003
XSS vulnerability in the Description Area of the Admin Profile
Reference>