CVE-2018-1355: Medium severity fortinet fortianalyzer vulnerability
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1355?
The severity of CVE-2018-1355 is medium.
How does CVE-2018-1355 affect Fortinet FortiAnalyzer and FortiManager?
CVE-2018-1355 affects Fortinet FortiAnalyzer versions 5.6.5 and below, and FortiManager versions 5.6.5 and below.
What is an open redirect vulnerability?
An open redirect vulnerability is a security flaw that allows an attacker to redirect a user to a malicious website.
What are the possible impacts of CVE-2018-1355?
CVE-2018-1355 could allow an attacker to inject malicious script code and potentially conduct social engineering attacks.
Are there any known fixes for CVE-2018-1355?
Currently, there are no known fixes for CVE-2018-1355. It is recommended to apply any available security patches or updates from the vendor.