An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.
2020-09-24T15:15:13.173
2024-11-21T05:00:20.053
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortianalyzer | 6.2.5 | Yes |
Application | fortinet | fortianalyzer | 6.4.0 | Yes |
Application | fortinet | fortianalyzer | 6.4.1 | Yes |
Application | fortinet | fortitester | ≤ 3.7.0 | Yes |
Application | fortinet | fortitester | 3.8.0 | Yes |