PT-2020-6792 · Fortinet · Fortianalyzer

Published

2020-09-21

·

Updated

2021-07-21

·

CVE-2020-12817

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiAnalyzer versions prior to 6.4.1 FortiAnalyzer versions prior to 6.2.5
Description The issue is related to the improper handling of the Name parameter in the Storage Connectors component of FortiAnalyzer, allowing a remote attacker to inject HTML tags. This could enable cross-site scripting attacks via IPv4/IPv6 address fields.
Recommendations For FortiAnalyzer versions prior to 6.4.1, update to version 6.4.1 or later. For FortiAnalyzer versions prior to 6.2.5, update to version 6.2.5 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06513
CVE-2020-12817

Affected Products

Fortianalyzer