CVE-2018-1351

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
28/06/2018
Last modified:
22/01/2020

Description

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 6.0.0 (including)