PT-2018-11890 · Fortinet · Fortimanager

Published

2018-06-28

·

Updated

2020-01-22

·

CVE-2018-1351

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiManager versions 5.6.6 and below Fortinet FortiManager version 6.0.0
Description A Cross-site Scripting (XSS) issue allows an attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log.
Recommendations For Fortinet FortiManager versions 5.6.6 and below, update to a version above 5.6.6 to resolve the issue. For Fortinet FortiManager version 6.0.0, update to a version above 6.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the remote device CLI config installation log to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1351

Affected Products

Fortimanager