First published: Tue Nov 01 2022(Updated: )
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiManager and FortiAnalyzer report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiManager | ||
Fortinet FortiAnalyzer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-21-228 is rated as high due to the potential for XSS attacks.
To fix FG-IR-21-228, update to the latest versions of FortiManager and FortiAnalyzer that address the vulnerability.
FG-IR-21-228 affects all versions of FortiManager and FortiAnalyzer that do not have the patch applied.
FG-IR-21-228 can enable a low privilege level attacker to perform an XSS attack through crafted comments.
The underlying issue in FG-IR-21-228 is improper neutralization of input during web page generation.