First published: Thu Jun 04 2020(Updated: )
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | <6.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this FortiAnalyzer vulnerability is CVE-2020-6640.
The severity of CVE-2020-6640 is medium with a CVSS score of 5.4.
The affected software for CVE-2020-6640 is Fortinet FortiAnalyzer version up to 6.2.4.
CVE-2020-6640 may allow a remote authenticated attacker to perform a stored cross-site scripting (XSS) attack via the Description Area in the Admin Profile of FortiAnalyzer.
Yes, please refer to the FortiGuard advisory FG-IR-20-003 for information on how to fix CVE-2020-6640.