QID 377729
Date Published: 2022-11-03
QID 377729: FortiAnalyzer - Cross-Site Scripting (XSS) Vulnerability (FG-IR-20-092)
An improper neutralization of input during web page generation [CWE-79] in FortiAnalyzer may allow an attacker to perform a stored Cross Site Scripting (XSS) attack via specifically crafted requests to the web GUI.
Affected Products:
FortiAnalyzer versions 6.0.6 and below.
FortiAnalyzer version 6.4.4.
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiAnalyzer
Vulnerable version may allow an attacker to perform a Cross Site Scripting (XSS)attack via specifically crafted requests to the web GUI
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-20-092
Vendor References
- FG-IR-20-092 -
www.fortiguard.com/psirt/FG-IR-20-092
CVEs related to QID 377729
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-092 |
|