QID 376130

Date Published: 2021-12-07

QID 376130: FortiGate FortiManager and FortiAnalyzer Cross-Site Scripting (XSS) Vulnerability (CWE-79)

FortiManager provides centralized policy-based provisioning, device configuration, and update management for FortiGate, FortiWiFi, and FortiMail appliances, and FortiClient end-point security agents, plus end-to-end network monitoring and device control.

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.The vulnerability exists due to insufficient sanitization of user-supplied data in FortiManager and FortiAnalyzer user interface. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website

Affected Products:
FortiManager Versions: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 7.0.0
FortiAnalyzer Versions: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 7.0.0

QID Detection Logic(Authenticated):
QID will fire the command to get system status and will match the affected version

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change the appearance of the web page, perform phishing and drive-by-download attacks.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution

    Customers are advised to refer to CVE-2021-32597 for more information.

    CVEs related to QID 376130

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-32597 URL Logo www.cybersecurity-help.cz/vdb/SB2021080318