First published: Wed Jun 27 2018(Updated: )
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | <=5.6.5 | |
Fortinet FortiAnalyzer | =6.0.0 | |
Fortinet FortiManager | <=5.6.5 | |
Fortinet FortiManager | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1355 is medium.
CVE-2018-1355 affects Fortinet FortiAnalyzer versions 5.6.5 and below, and FortiManager versions 5.6.5 and below.
An open redirect vulnerability is a security flaw that allows an attacker to redirect a user to a malicious website.
CVE-2018-1355 could allow an attacker to inject malicious script code and potentially conduct social engineering attacks.
Currently, there are no known fixes for CVE-2018-1355. It is recommended to apply any available security patches or updates from the vendor.