Reflected cross-site scripting vulnerability in login handler

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWeb may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests to the login webpage.

Affected Products

FortiWeb version 6.2.0 through 6.2.7
FortiWeb version 6.3.0 through 6.3.15
FortiWeb version 6.4.0 through 6.4.1

Solutions

Upgrade to FortiWeb version 7.0.0 or above.
Upgrade to FortiWeb version 6.4.2 or above.
Upgrade to FortiWeb version 6.3.16 or above.

Acknowledgement

Fortinet is pleased to thank Hari Regmi for reporting this vulnerability under responsible disclosure.

Timeline

2021-12-07: Initial publication