FG-IR-21-228: XSS Vulnerability in Report Templates
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiManager and FortiAnalyzer report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-21-228?
The severity of FG-IR-21-228 is rated as high due to the potential for XSS attacks.
How do I fix FG-IR-21-228?
To fix FG-IR-21-228, update to the latest versions of FortiManager and FortiAnalyzer that address the vulnerability.
What versions of Fortinet software are affected by FG-IR-21-228?
FG-IR-21-228 affects all versions of FortiManager and FortiAnalyzer that do not have the patch applied.
What type of attack can FG-IR-21-228 enable?
FG-IR-21-228 can enable a low privilege level attacker to perform an XSS attack through crafted comments.
What is the underlying issue in FG-IR-21-228?
The underlying issue in FG-IR-21-228 is improper neutralization of input during web page generation.