FortiOS Reflected XSS in Web Proxy Disclaimer Response web page
Cross-site Scripting (XSS)
FortiOS 5.4.0 to 5.4.5
FortiOS 5.2.0 to 5.2.11
Upgrade to FortiOS 5.2.12, 5.4.6 or 5.6.1
In System->Replacement Messages->Web-proxy->"Web-proxy HTTP Error Page", remove the following default message content:
2018-05-14 Add workaround for old FortiOS versions.
2017-11-03 Initial version.
Fortinet is pleased to thank "usd AG" and "Serge Ivanov of Payvision BV" for reporting this vulnerability under responsible disclosure.