PT-2018-18910 · Fortinet · Fortiauthenticator
Published
2018-05-31
·
Updated
2019-04-22
·
CVE-2018-9186
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiAuthenticator versions 4.0.0 through 5.3.0
Description
A cross-site scripting (XSS) issue exists due to a CSRF validation failure, allowing an attacker to execute unauthorized script code by injecting malicious scripts in the HTTP referer header.
Recommendations
For versions 4.0.0 through 5.3.0, update to a version that includes the fix for the CSRF validation failure issue to prevent XSS attacks.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiauthenticator