CVE-2020-12811: XSS
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12811?
The severity of CVE-2020-12811 is medium.
What is the affected software for CVE-2020-12811?
The affected software for CVE-2020-12811 is FortiManager versions 6.2.0 to 6.2.6 and FortiAnalyzer versions 6.2.0 to 6.2.6.
What is the vulnerability description of CVE-2020-12811?
CVE-2020-12811 is a vulnerability in FortiManager and FortiAnalyzer that allows an attacker to execute cross-site scripting (XSS) attacks via the Identify Provider name field.
How can an attacker exploit CVE-2020-12811?
An attacker can exploit CVE-2020-12811 by injecting malicious scripts into the Identify Provider name field in a web page.
Is there a fix available for CVE-2020-12811?
Yes, Fortinet has released patches for FortiManager and FortiAnalyzer to address the vulnerability. It is recommended to update to the latest version to mitigate the risk.