CVE-2020-15937: XSS
An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15937?
CVE-2020-15937 is rated as a medium severity vulnerability that can lead to stored cross site scripting attacks.
How do I fix CVE-2020-15937?
To fix CVE-2020-15937, upgrade FortiGate to version 6.2.5 or 6.4.1 or later.
What systems are affected by CVE-2020-15937?
CVE-2020-15937 affects FortiGate systems running FortiOS versions 6.2.x below 6.2.5 and 6.4.x below 6.4.1.
What type of attack does CVE-2020-15937 allow?
CVE-2020-15937 allows remote attackers to perform stored cross site scripting (XSS) attacks via the IPS and WAF logs dashboard.
What is the potential impact of CVE-2020-15937?
The potential impact of CVE-2020-15937 includes unauthorized data access and manipulation through successful XSS exploitation.