CVE-2018-13380: XSS
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13380?
CVE-2018-13380 is a Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS and Fortinet FortiProxy.
How does CVE-2018-13380 affect Fortinet FortiOS and Fortinet FortiProxy?
CVE-2018-13380 allows an attacker to execute unauthorized malicious script code via the error or message handling parameter in the SSL VPN web portal.
What versions of Fortinet FortiOS and Fortinet FortiProxy are affected by CVE-2018-13380?
Fortinet FortiOS versions 5.2 and below, 5.4.0 to 5.4.12, 5.6.0 to 5.6.7, and 6.0.0 to 6.0.4, as well as Fortinet FortiProxy versions 1.2.8 and below, and version 2.0.0 are affected.
What is the severity of CVE-2018-13380?
CVE-2018-13380 has a severity of medium, with a CVSS score of 6.1.
How can I fix CVE-2018-13380?
To fix CVE-2018-13380, update Fortinet FortiOS to version 6.0.5, 5.6.8, 5.4.13, or later, and update Fortinet FortiProxy to version 2.0.1 or later.