Reflected cross-site scripting vulnerability in cgi_bin handlers

Summary

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiWLM may allow an
authenticated user to perform an XSS attack via crafted HTTP GET requests.

Affected Products

FortiWLM version 8.6.2 and below
FortiWLM 8.2 all versions
FortiWLM 8.3 all versions
FortiWLM 8.4 all versions
FortiWLM 8.5 all versions

Solutions

Upgrade to FortiWLM version 8.6.3 or above.

Acknowledgement

Internally discovered and reported by Mattia Fecit of Fortinet Product Security Team.

Timeline

2021-12-07: Initial publication