Persistent XSS in Log pages
Summary
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via HTTP fields observed in the traffic and event logviews.
| Version | Affected | Solution |
|---|---|---|
| FortiADC 7.1 | Not affected | Not Applicable |
| FortiADC 7.0 | 7.0.0 through 7.0.2 | Upgrade to 7.0.3 or above |
| FortiADC 6.2 | 6.2.0 through 6.2.3 | Upgrade to 6.2.4 or above |
| FortiADC 6.1 | Not affected | Not Applicable |
| FortiADC 6.0 | Not affected | Not Applicable |
| FortiADC 5.4 | Not affected | Not Applicable |
| FortiADC 5.3 | Not affected | Not Applicable |
| FortiADC 5.2 | Not affected | Not Applicable |
| FortiADC 5.1 | Not affected | Not Applicable |