Cross-site Scripting Vulnerability in Fortinet FortiOS and FortiProxy
CVE-2018-13380
4.7MEDIUM
Summary
A Cross-site Scripting (XSS) vulnerability exists in Fortinet's FortiOS and FortiProxy products that could allow an attacker to execute unauthorized script code. This risk arises from improper handling of error messages and parameters within the SSL VPN web portal, affecting several versions of the software. Exploitation of this vulnerability could lead to significant security concerns, including data theft and unauthorized access to sensitive user information.
Affected Version(s)
Fortinet FortiOS and FortiProxy FortiGate 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4.0 through 5.4.12, 5.2 and earlier and FortiProxy versions 2.0.0, 1.2.8 and earlier
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved