[FortiOS] Injection attacks in the WAF and IPS logs
Summary
An improper neutralization of input vulnerability in the FortiGate may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard.
Affected Products
FortiGate version 6.2.2 to 6.2.5.
FortiGate version 6.4.1 and below.
Please note that FortiGate version 5.6.x, 6.0.x, 6.2.0, 6.2.1 are NOT impacted by this issue.
Solutions
Please upgrade to FortiGate version 6.4.2 or above.
Please upgrade to FortiGate version 6.2.6 or above.
Acknowledgement
Fortinet is pleased to thank Forster Chiu from CYBERGROOT LTD; Mark Chapman of Chapman Technology Group, Inc; Wenceslas Lejeune and the SOC team from Cheops Technology and Oğuz DOKUMACI from Oyuncusundan.com for reporting this vulnerability under responsible disclosure.Timeline
2020-12-01: Initial publication