FortiWeb - Reflected cross-site scripting in SAML login
An improper neutralization of input during web page generation vulnerabilityÂ [CWE-79] in FortiWeb may allow an unauthenticated attacker to perform an XSS attackÂ via crafted HTTP GET requests to the SAML login webpage.
FortiWeb version 6.4.1 and 6.4.0.
Upgrade to the upcoming FortiWeb version 7.0.0 or above.
Upgrade to FortiWeb version 6.4.2Â or above.