QID 378007
Date Published: 2023-03-09
QID 378007: Fortinet FortiManager FortiAnalyzer Cross-Site Scripting (XSS) Vulnerability (FG-IR-21-228)
An improper neutralization of input during web page generation vulnerability in FortiManager and FortiAnalyzer report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment.
Affected Products:
FortiAnalyzer version 7.0.0 through 7.0.4
FortiAnalyzer version 6.4.0 through 6.4.8
FortiAnalyzer 6.2 all versions
FortiAnalyzer 6.0 all versions
FortiManager version 7.0.0 through 7.0.4
FortiManager version 6.4.0 through 6.4.8
FortiManager 6.2 all versions
FortiManager 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager,FortiAnalyzer
Vulnerable version may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-228
- FG-IR-21-228 -
www.fortiguard.com/psirt/FG-IR-21-228
CVEs related to QID 378007
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-228 |
|