A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "param" parameter of the error process HTTP requests.
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-19-034 | Mitigation Vendor Advisory |
http://www.securityfocus.com/bid/108610 |
Configurations
Information
Published : 2019-06-04 15:29
Updated : 2019-10-23 13:15
NVD link : CVE-2019-5586
Mitre link : CVE-2019-5586
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
fortinet
- fortios