Stored XSS vulnerability in external resource page

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted IP Address.

Version Affected Solution
FortiADC 7.1 7.1.0 Upgrade to 7.1.1 or above
FortiADC 7.0 Not affected Not Applicable
FortiADC 6.2 Not affected Not Applicable
FortiADC 6.1 Not affected Not Applicable
FortiADC 6.0 Not affected Not Applicable
FortiADC 5.4 Not affected Not Applicable
FortiADC 5.3 Not affected Not Applicable
FortiADC 5.2 Not affected Not Applicable
FortiADC 5.1 Not affected Not Applicable

Timeline

2022-11-01: Initial publication