Input Injection Vulnerability in FortiClientEMS by Fortinet
CVE-2020-15940
4.1MEDIUM
What is CVE-2020-15940?
An improper neutralization of input vulnerability allows a remote authenticated attacker to exploit vulnerable versions of FortiClientEMS by injecting malicious scripts or tags through the name parameter in various sections of the server. This vulnerability affects versions 6.4.1 and below and 6.2.9 and below, posing significant risks to web security and integrity.
Affected Version(s)
Fortinet FortiClientEMS FortiClientEMS 6.4.1, 6.4.0, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.8, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0