PT-2020-13274 · Fortinet · Fortimanager+1
Published
2020-09-24
·
Updated
2020-09-30
·
CVE-2020-12811
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FortiManager versions 6.2.0 through 6.2.3
FortiAnalyzer versions 6.2.0 through 6.2.3
Description
The issue is related to an improper neutralization of script-related HTML tags in a web page, which may allow an attacker to execute a cross-site scripting (XSS) attack via the
Identify Provider name field.Recommendations
For FortiManager versions 6.2.0 through 6.2.3, update to a version that fixes this issue.
For FortiAnalyzer versions 6.2.0 through 6.2.3, update to a version that fixes this issue.
As a temporary workaround, consider restricting access to the Identify Provider name field to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortianalyzer
Fortimanager