QID 44094
Date Published: 2023-07-28
QID 44094: FortiOS - Cross Site Scripting (XSS) Vulnerability (FG-IR-20-068)
An improper neutralization of input vulnerability in the FortiGate may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard.
Affected Versions:
FortiOS 6.2.x versions 6.2.0 to 6.2.5.
FortiOS 6.4.x version 6.4.1 and below
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Note: Making this QID practice as this QID is only supported for Fortios product also banner based detection added
Successful exploitation of the vulnerability may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-20-068
Vendor References
- FG-IR-20-068 -
www.fortiguard.com/psirt/FG-IR-20-068
CVEs related to QID 44094
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-068 |
|