
====================================================================

                             CERT-Renater

                 Note d'Information No. 2020/VULN344
_____________________________________________________________________

DATE                : 12/06/2020

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running FortiAnalyzer versions prior to
                                           6.2.3.

=====================================================================
https://fortiguard.com/psirt/FG-IR-20-003
_____________________________________________________________________

XSS vulnerability in the Description Area of the Admin Profile


Summary

An improper neutralization of input vulnerability in the Admin Profile
of FortiAnalyzer may allow a remote authenticated attacker to perform a
stored cross site scripting attack (XSS) via the Description Area.


Impact

Unauthorized code execution


Affected Products

FortiAnalyzer version 6.2.3 and below.


Solutions

Please upgrade to FortiAnalyzer version 6.2.4 or above.

Please upgrade to FortiAnalyzer version 6.4.0 or above.


Acknowledgement

Fortinet is pleased to thank Ali Ardic from Trend Micro for reporting
this vulnerability under responsible disclosure.

=========================================================
+ CERT-RENATER        | tel : 01-53-94-20-44            +
+ 23/25 Rue Daviel    | fax : 01-53-94-20-41            +
+ 75013 Paris         | email:cert@support.renater.fr   +
=========================================================





