Persistent XSS in Log pages

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via HTTP fields observed in the traffic and event logviews.

Version Affected Solution
FortiADC 7.1 Not affected Not Applicable
FortiADC 7.0 7.0.0 through 7.0.2 Upgrade to 7.0.3 or above
FortiADC 6.2 6.2.0 through 6.2.3 Upgrade to 6.2.4 or above

Acknowledgement

Fortinet is pleased to thank Almas Zhurtanov and Tom Tervoort from Secura for reporting this vulnerability under responsible disclosure.

Timeline

2022-11-01: Initial publication