Input Vulnerability in FortiAnalyzer Admin Profile Exposes Users
CVE-2020-6640
5.4MEDIUM
What is CVE-2020-6640?
An input vulnerability exists within the Admin Profile of FortiAnalyzer that may permit a remote authenticated attacker to exploit the system. By leveraging this flaw, an attacker can perform a stored cross-site scripting (XSS) attack via the Description Area, potentially leading to unauthorized actions and compromised user data.
Affected Version(s)
Fortinet FortiAnalyzer FortiAnalyzer 6.2.3, 6.2.2