PSIRT Advisory

FortiManager XSS vulnerability when view config under Revision History

Summary

A potential Cross-site Scripting (XSS) vulnerability exists in FortiManager: Displayed data is not sanitized when an administrator views the managed devices configuration, in the installation revision history of the GUI.

The risk of successful exploitation is however low, because injection of malicious code needs to happen in the managed device’s CLI configurations, which are generally trusted.

Impact

Cross-site Scripting (XSS)

Affected Products

FortiManager 6.0.0 and below versions

Solutions

Upgrade to FortiManager 6.0.1 or above.

Acknowledgement

Fortinet is pleased to thank Sven Wandersleb, link protect GmbH reporting this vulnerability under responsible disclosure.