Cross site scripting in FortiProxy SSL VPN portal

Summary

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).

Affected Products

FortiProxy version 2.0.0.
FortiProxy versions 1.2.9 and below.

Solutions

Please upgrade to FortiProxy version 2.0.1 or above. Please upgrade to FortiProxy version 1.2.10 or above.

Acknowledgement

Fortinet is pleased to thank Qingtang Zheng from CodeSafe Team of Legendsec at Qi'anXin Group and Choudhary Muhammad Osama from BankIslami Pakistan Limited for bringing this issue to our attention under responsible disclosure.

Timeline

2021-05-05: Initial publication