An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user’s web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.
[
{
"product": "Fortinet FortiOS",
"vendor": "Fortinet",
"versions": [
{
"status": "affected",
"version": "FortiOS 6.0.0 and below"
}
]
}
]