imPC@ndo IT

Tracker / CVE-2020-6647

CVE-2020-6647

Medium 5.4

An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.

Affected products and versions

fortinet fortiadc_firmware
fortinet fortiadc_firmware · … → 5.3.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References