CVE-2020-12817: XSS
Published Sep 24, 2020
·Updated
An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.
Affected Software
5 affected components
Fortinet FortiAnalyzer=6.2.5
Fortinet FortiAnalyzer=6.4.0
Fortinet FortiAnalyzer=6.4.1
Fortinet FortiTester<=3.7.0
Fortinet FortiTester=3.8.0
Event History
Sep 24, 2020
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-12817.
2
What is the severity level of CVE-2020-12817?
The severity level of CVE-2020-12817 is high, with a severity value of 8.8.
3
Which software versions are affected by CVE-2020-12817?
FortiAnalyzer versions 6.2.5, 6.4.0, and 6.4.1 are affected by CVE-2020-12817.
4
How can a remote attacker exploit CVE-2020-12817?
A remote authenticated attacker can exploit CVE-2020-12817 by injecting script-related HTML tags via the Name parameter of Storage Connectors.
5
Where can I find more information about CVE-2020-12817?
You can find more information about CVE-2020-12817 at the following reference: https://fortiguard.com/advisory/FG-IR-20-054