Cross-site Scripting Vulnerability in Fortinet FortiOS and FortiProxy
CVE-2018-13380

4.7MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
4 June 2019

Summary

A Cross-site Scripting (XSS) vulnerability exists in Fortinet's FortiOS and FortiProxy products that could allow an attacker to execute unauthorized script code. This risk arises from improper handling of error messages and parameters within the SSL VPN web portal, affecting several versions of the software. Exploitation of this vulnerability could lead to significant security concerns, including data theft and unauthorized access to sensitive user information.

Affected Version(s)

Fortinet FortiOS and FortiProxy FortiGate 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4.0 through 5.4.12, 5.2 and earlier and FortiProxy versions 2.0.0, 1.2.8 and earlier

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.