An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below, 5.3.6 and below, 5.2.6 and below, 5.1.2 and below, 5.0.3 and below, 4.2.2 and below, 4.1.2 and below, 4.0.4 and below may allow a remote and unauthenticated attacker to perform an XSS attack via sending a crafted request with an invalid lang parameter or with an invalid org.springframework.web.servlet.i18n.CookieLocaleResolver.LOCALE value.
2021-08-19T00:15:07.560
2024-11-21T06:07:21.377
Modified
CVSSv3.1: 5.8 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiportal | ≤ 4.0.4 | Yes |
Application | fortinet | fortiportal | ≤ 4.1.2 | Yes |
Application | fortinet | fortiportal | ≤ 4.2.2 | Yes |
Application | fortinet | fortiportal | ≤ 5.0.3 | Yes |
Application | fortinet | fortiportal | ≤ 5.1.2 | Yes |
Application | fortinet | fortiportal | ≤ 5.2.6 | Yes |
Application | fortinet | fortiportal | ≤ 5.3.6 | Yes |
Application | fortinet | fortiportal | ≤ 6.0.4 | Yes |