QID 376130
Date Published: 2021-12-07
QID 376130: FortiGate FortiManager and FortiAnalyzer Cross-Site Scripting (XSS) Vulnerability (CWE-79)
FortiManager provides centralized policy-based provisioning, device configuration, and update management for FortiGate, FortiWiFi, and FortiMail appliances, and FortiClient end-point security agents, plus end-to-end network monitoring and device control.
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.The vulnerability exists due to insufficient sanitization of user-supplied data in FortiManager and FortiAnalyzer user interface. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website
Affected Products:
FortiManager Versions: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 7.0.0
FortiAnalyzer Versions: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 7.0.0
QID Detection Logic(Authenticated):
QID will fire the command to get system status and will match the affected version
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change the appearance of the web page, perform phishing and drive-by-download attacks.
Customers are advised to refer to CVE-2021-32597 for more information.
- CVE-2021-32597 -
www.cybersecurity-help.cz/vdb/SB2021080318 - FG-IR-21-054 -
fortiguard.com/advisory/FG-IR-21-054
CVEs related to QID 376130
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-32597 |
|