XSS vulnerability in FortiGate DHCP monitor page

Summary

An Improper Neutralization of Input vulnerability in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate to perform a Stored Cross Site Scripting attack (XSS) by sending a crafted DHCP packet.

Affected Products

FortiOS version 6.2.1 and below.
FortiOS version 6.0.6 and below.

Solutions

Please upgrade to FortiOS version 6.2.2 and above.

Please upgrade to FortiOS version 6.0.7 and above.