<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Multiple reflected XSS</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-21-054</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2021-08-03T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2021-08-03T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2021-08-03T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer user interface may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET parameters.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiAnalyzer version 7.0.0FortiAnalyzer version 6.4.0 through 6.4.5FortiAnalyzer version 6.2.0 through 6.2.7FortiAnalyzer 6.0 all versionsFortiAnalyzer 5.6 all versions are not affectedFortiManager version 7.0.0FortiManager version 6.4.0 through 6.4.5FortiManager version 6.2.0 through 6.2.7FortiManager 6.0 all versionsFortiManager 5.6 all versions are not affected
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiManager version 6.2.8.Please upgrade to FortiManager version 6.4.6.Please upgrade to FortiManager version 7.0.1.Please upgrade to FortiAnalyzer version 6.2.8.Please upgrade to FortiAnalyzer version 6.4.6.Please upgrade to FortiAnalyzer version 7.0.1.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank Clément Amic, Pierre Milioni and Adrien Peter from Synacktiv for reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiAnalyzer" Type="Product Name">
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.0">FortiAnalyzer 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.5">FortiAnalyzer 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.4">FortiAnalyzer 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.3">FortiAnalyzer 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.2">FortiAnalyzer 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.1">FortiAnalyzer 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.0">FortiAnalyzer 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.7">FortiAnalyzer 6.2.7</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.6">FortiAnalyzer 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.5">FortiAnalyzer 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.4">FortiAnalyzer 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.3">FortiAnalyzer 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.2">FortiAnalyzer 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.1">FortiAnalyzer 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.0">FortiAnalyzer 6.2.0</FullProductName>
                </Branch>
                <Branch Name="6.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.12">FortiAnalyzer 6.0.12</FullProductName>
                </Branch>
                <Branch Name="6.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.11">FortiAnalyzer 6.0.11</FullProductName>
                </Branch>
                <Branch Name="6.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.10">FortiAnalyzer 6.0.10</FullProductName>
                </Branch>
                <Branch Name="6.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.9">FortiAnalyzer 6.0.9</FullProductName>
                </Branch>
                <Branch Name="6.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.8">FortiAnalyzer 6.0.8</FullProductName>
                </Branch>
                <Branch Name="6.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.7">FortiAnalyzer 6.0.7</FullProductName>
                </Branch>
                <Branch Name="6.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.6">FortiAnalyzer 6.0.6</FullProductName>
                </Branch>
                <Branch Name="6.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.5">FortiAnalyzer 6.0.5</FullProductName>
                </Branch>
                <Branch Name="6.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.4">FortiAnalyzer 6.0.4</FullProductName>
                </Branch>
                <Branch Name="6.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.3">FortiAnalyzer 6.0.3</FullProductName>
                </Branch>
                <Branch Name="6.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.2">FortiAnalyzer 6.0.2</FullProductName>
                </Branch>
                <Branch Name="6.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.1">FortiAnalyzer 6.0.1</FullProductName>
                </Branch>
                <Branch Name="6.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.0.0">FortiAnalyzer 6.0.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiManager" Type="Product Name">
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.0">FortiManager 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.5">FortiManager 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.4">FortiManager 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.3">FortiManager 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.2">FortiManager 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.1">FortiManager 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.0">FortiManager 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.7">FortiManager 6.2.7</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.6">FortiManager 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.5">FortiManager 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.4">FortiManager 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.3">FortiManager 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.2">FortiManager 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.1">FortiManager 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.0">FortiManager 6.2.0</FullProductName>
                </Branch>
                <Branch Name="6.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.12">FortiManager 6.0.12</FullProductName>
                </Branch>
                <Branch Name="6.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.11">FortiManager 6.0.11</FullProductName>
                </Branch>
                <Branch Name="6.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.10">FortiManager 6.0.10</FullProductName>
                </Branch>
                <Branch Name="6.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.9">FortiManager 6.0.9</FullProductName>
                </Branch>
                <Branch Name="6.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.8">FortiManager 6.0.8</FullProductName>
                </Branch>
                <Branch Name="6.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.7">FortiManager 6.0.7</FullProductName>
                </Branch>
                <Branch Name="6.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.6">FortiManager 6.0.6</FullProductName>
                </Branch>
                <Branch Name="6.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.5">FortiManager 6.0.5</FullProductName>
                </Branch>
                <Branch Name="6.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.4">FortiManager 6.0.4</FullProductName>
                </Branch>
                <Branch Name="6.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.3">FortiManager 6.0.3</FullProductName>
                </Branch>
                <Branch Name="6.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.2">FortiManager 6.0.2</FullProductName>
                </Branch>
                <Branch Name="6.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.1">FortiManager 6.0.1</FullProductName>
                </Branch>
                <Branch Name="6.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.0.0">FortiManager 6.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Multiple reflected XSS</Title>
        <cvrf:CVE>CVE-2021-32597</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiAnalyzer-7.0.0</ProductID>
                <ProductID>FortiAnalyzer-6.4.5</ProductID>
                <ProductID>FortiAnalyzer-6.4.4</ProductID>
                <ProductID>FortiAnalyzer-6.4.3</ProductID>
                <ProductID>FortiAnalyzer-6.4.2</ProductID>
                <ProductID>FortiAnalyzer-6.4.1</ProductID>
                <ProductID>FortiAnalyzer-6.4.0</ProductID>
                <ProductID>FortiAnalyzer-6.2.7</ProductID>
                <ProductID>FortiAnalyzer-6.2.6</ProductID>
                <ProductID>FortiAnalyzer-6.2.5</ProductID>
                <ProductID>FortiAnalyzer-6.2.4</ProductID>
                <ProductID>FortiAnalyzer-6.2.3</ProductID>
                <ProductID>FortiAnalyzer-6.2.2</ProductID>
                <ProductID>FortiAnalyzer-6.2.1</ProductID>
                <ProductID>FortiAnalyzer-6.2.0</ProductID>
                <ProductID>FortiAnalyzer-6.0.12</ProductID>
                <ProductID>FortiAnalyzer-6.0.11</ProductID>
                <ProductID>FortiAnalyzer-6.0.10</ProductID>
                <ProductID>FortiAnalyzer-6.0.9</ProductID>
                <ProductID>FortiAnalyzer-6.0.8</ProductID>
                <ProductID>FortiAnalyzer-6.0.7</ProductID>
                <ProductID>FortiAnalyzer-6.0.6</ProductID>
                <ProductID>FortiAnalyzer-6.0.5</ProductID>
                <ProductID>FortiAnalyzer-6.0.4</ProductID>
                <ProductID>FortiAnalyzer-6.0.3</ProductID>
                <ProductID>FortiAnalyzer-6.0.2</ProductID>
                <ProductID>FortiAnalyzer-6.0.1</ProductID>
                <ProductID>FortiAnalyzer-6.0.0</ProductID>
                <ProductID>FortiManager-7.0.0</ProductID>
                <ProductID>FortiManager-6.4.5</ProductID>
                <ProductID>FortiManager-6.4.4</ProductID>
                <ProductID>FortiManager-6.4.3</ProductID>
                <ProductID>FortiManager-6.4.2</ProductID>
                <ProductID>FortiManager-6.4.1</ProductID>
                <ProductID>FortiManager-6.4.0</ProductID>
                <ProductID>FortiManager-6.2.7</ProductID>
                <ProductID>FortiManager-6.2.6</ProductID>
                <ProductID>FortiManager-6.2.5</ProductID>
                <ProductID>FortiManager-6.2.4</ProductID>
                <ProductID>FortiManager-6.2.3</ProductID>
                <ProductID>FortiManager-6.2.2</ProductID>
                <ProductID>FortiManager-6.2.1</ProductID>
                <ProductID>FortiManager-6.2.0</ProductID>
                <ProductID>FortiManager-6.0.12</ProductID>
                <ProductID>FortiManager-6.0.11</ProductID>
                <ProductID>FortiManager-6.0.10</ProductID>
                <ProductID>FortiManager-6.0.9</ProductID>
                <ProductID>FortiManager-6.0.8</ProductID>
                <ProductID>FortiManager-6.0.7</ProductID>
                <ProductID>FortiManager-6.0.6</ProductID>
                <ProductID>FortiManager-6.0.5</ProductID>
                <ProductID>FortiManager-6.0.4</ProductID>
                <ProductID>FortiManager-6.0.3</ProductID>
                <ProductID>FortiManager-6.0.2</ProductID>
                <ProductID>FortiManager-6.0.1</ProductID>
                <ProductID>FortiManager-6.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>4.4</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:P/RL:X/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-21-054</URL>
                <Description>Multiple reflected XSS</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>