CVE-2019-16154: XSS
An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16154?
CVE-2019-16154 is a vulnerability that allows an unauthenticated user to perform a cross-site scripting attack (XSS) in FortiAuthenticator WEB UI 6.0.0.
How severe is CVE-2019-16154?
CVE-2019-16154 has a severity keyword of medium and a severity value of 6.1.
What software version is affected by CVE-2019-16154?
FortiAuthenticator WEB UI version 6.0.0 is affected by CVE-2019-16154.
How can an attacker exploit CVE-2019-16154?
An attacker can exploit CVE-2019-16154 by using a parameter of the logon page to perform a cross-site scripting attack (XSS).
Is there a fix for CVE-2019-16154?
At this time, there is no known fix or patch available for CVE-2019-16154. It is recommended to follow the vendor's advisory for any updates or mitigations.