First published: Tue Apr 07 2020(Updated: )
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet Fortiadc Firmware | <=5.3.4 | |
Fortinet Fortiadc Firmware | =5.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6647 is an improper neutralization of input vulnerability in the dashboard of FortiADC.
CVE-2020-6647 may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.
FortiADC firmware versions up to and including 5.3.4 and 5.4.0 are affected by CVE-2020-6647.
CVE-2020-6647 has a severity rating of medium with a value of 5.4.
To fix CVE-2020-6647, upgrade to a version of FortiADC firmware that is not affected, or apply the patch provided by Fortinet.