Description
A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.
Affected products
- fortinet / Fortinet FortiPortal4.0.0 and below – 4.0.0 and below
References
- VENDOR_ADVISORYhttps://fortiguard.com/psirt/FG-IR-17-114