CVE-2020-6647: XSS
Published Apr 7, 2020
·Updated
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.
Affected Software
2 affected components
Fortinet Fortiadc Firmware<=5.3.4
Fortinet Fortiadc Firmware=5.4.0
Event History
Apr 7, 2020
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-6647?
CVE-2020-6647 is an improper neutralization of input vulnerability in the dashboard of FortiADC.
2
What is the impact of CVE-2020-6647?
CVE-2020-6647 may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.
3
What software is affected by CVE-2020-6647?
FortiADC firmware versions up to and including 5.3.4 and 5.4.0 are affected by CVE-2020-6647.
4
How severe is CVE-2020-6647?
CVE-2020-6647 has a severity rating of medium with a value of 5.4.
5
How can I fix CVE-2020-6647?
To fix CVE-2020-6647, upgrade to a version of FortiADC firmware that is not affected, or apply the patch provided by Fortinet.