CVE-2020-12815: XSS
Published Sep 24, 2020
·Updated
An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields.
Affected Software
4 affected components
Fortinet FortiAnalyzer<=6.2.5
Fortinet FortiAnalyzer>=6.4.0<=6.4.1
Fortinet FortiTester<=3.7.0
Fortinet FortiTester=3.8.0
Event History
Sep 24, 2020
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-12815?
CVE-2020-12815 is an improper neutralization of input vulnerability in FortiTester before version 3.9.0.
2
How does CVE-2020-12815 impact FortiAnalyzer?
FortiAnalyzer versions up to and including 6.2.5 are affected by CVE-2020-12815.
3
Is FortiAnalyzer version 6.4.1 affected by CVE-2020-12815?
No, FortiAnalyzer version 6.4.1 is not affected by CVE-2020-12815.
4
What is the severity of CVE-2020-12815?
The severity of CVE-2020-12815 is medium (CVSS score of 5.4).
5
How can I fix CVE-2020-12815 in FortiTester?
To fix CVE-2020-12815, upgrade FortiTester to version 3.9.0 or later.