PSIRT Advisory

XSS vulnerability in the URL Description of URL filter

Summary

An improper neutralization of input vulnerability in the URL Description of FortiIsolator may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via a parameter of the request.

Impact

Unauthorized code execution

Affected Products

FortiIsolator version 1.2.2 and below.

Solutions

Please upgrade to FortiIsolator version 2.0.0 or above.

Acknowledgement

Fortinet is pleased to thank Danilo Costa from PBI for reporting this vulnerability under responsible disclosure.