First published: Tue Jan 07 2020(Updated: )
An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAuthenticator | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16154 is a vulnerability that allows an unauthenticated user to perform a cross-site scripting attack (XSS) in FortiAuthenticator WEB UI 6.0.0.
CVE-2019-16154 has a severity keyword of medium and a severity value of 6.1.
FortiAuthenticator WEB UI version 6.0.0 is affected by CVE-2019-16154.
An attacker can exploit CVE-2019-16154 by using a parameter of the logon page to perform a cross-site scripting attack (XSS).
At this time, there is no known fix or patch available for CVE-2019-16154. It is recommended to follow the vendor's advisory for any updates or mitigations.