Cross Site Scripting (XSS) vulnerabilities over the Management Console

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiEDR Central Manager may allow a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) via injecting a malicious payload into the Management Console through various endpoints.

Affected Products

At least
FortiEDR 5.2 all versions are not affected
FortiEDR 5.1 all versions
FortiEDR 5.0 all versions
FortiEDR 4.0 all versions

Solutions

Please upgrade FortiEDR Central Manager to version 5.2.0 and above,

Please upgrade FortiEDR Central Manager to version 5.0.3 Patch 7 and above.

Timeline

2022-07-05: Initial publication