Lucene search

K
fortinetFortiGuard LabsFG-IR-21-228
HistoryNov 01, 2022 - 12:00 a.m.

FortiManager/FortiAnalyzer - XSS Vulnerability in Report Templates

2022-11-0100:00:00
FortiGuard Labs
www.fortiguard.com
133
fortimanager
fortianalyzer
xss vulnerability
report templates
cwe-79
low privilege attacker
xss attack
ckeditor
cve-2020-9281
software

0.002 Low

EPSS

Percentile

53.2%

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiManager and FortiAnalyzer report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor “protected” comment as described in CVE-2020-9281.