CVE-2020-15940: XSS
An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15940?
CVE-2020-15940 is an improper neutralization of input vulnerability in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below.
What is the severity of CVE-2020-15940?
CVE-2020-15940 has a severity rating of 5.4 (medium).
How does CVE-2020-15940 impact FortiClientEMS?
CVE-2020-15940 allows a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server.
Which versions of FortiClientEMS are affected by CVE-2020-15940?
FortiClientEMS versions 6.4.1 and below and 6.2.9 and below are affected by CVE-2020-15940.
How can I fix CVE-2020-15940 vulnerability?
To fix CVE-2020-15940, update FortiClientEMS to a version above 6.4.1 or 6.2.9, respectively.