
====================================================================

                             CERT-Renater

                 Note d'Information No. 2020/VULN525
_____________________________________________________________________

DATE                : 17/09/2020

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): FortiOS versions prior to 6.2.2, 6.0.9, 5.6.13.

=====================================================================
https://fortiguard.com/psirt/FG-IR-19-223
_____________________________________________________________________

XSS vulnerability in FortiOS SSLVPN Portal

IR Number : FG-IR-19-223

Date      : Sep 16, 2020

Risk      : 3/5

Impact    : Unauthorized code execution

CVE ID    : CVE-2019-15706

CVE ID    : CVE-2019-15706

Summary

An improper neutralization of input during web page generation in the
SSL VPN portal of FortiOS may allow a remote authenticated attacker to
perform a stored cross site scripting attack (XSS).

Impact

Unauthorized code execution

Affected Products

FortiOS version 6.2.1 and below. FortiOS version 6.0.8 and below.
FortiOS version 5.6.12 and below.


Solutions

Please upgrade to FortiOS version 6.2.2 or above. Please upgrade to
FortiOS version 6.0.9 or above. Please upgrade to FortiOS version 5.6.13
or above.


Acknowledgement

Fortinet is pleased to thank Qingtang Zheng from CodeSafe Team of
Legendsec at Qi'anXin Group and Choudhary Muhammad Osama for bringing
this issue to our attention under responsible disclosure.


=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================


