Lucene search

K
fortinetFortiGuard LabsFG-IR-19-070
HistoryJun 12, 2019 - 12:00 a.m.

Cross-Site-Scripting (XSS) vulnerabilty in Fortiweb reports

2019-06-1200:00:00
FortiGuard Labs
www.fortiguard.com
8

EPSS

0.001

Percentile

38.2%

The URL part of the report message is not encoded in Fortinet FortiWeb which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML format.

EPSS

0.001

Percentile

38.2%

Related for FG-IR-19-070