CVE-2019-5588Cross-site Scripting in Fortinet Fortios

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 50.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4
Latest updateMay 24

Description

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "err" parameter of the error process HTTP requests.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDfortinet/fortios6.0.06.0.4
CVEListV5fortinet/fortinet_fortiosFortiOS 6.0.0 to 6.0.4

🔴Vulnerability Details

2
GHSA
GHSA-c9fg-253c-5m34: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 62022-05-24
CVEList
CVE-2019-5588: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 62019-06-04

📋Vendor Advisories

1
Fortinet
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN w...2019-06-04
CVE-2019-5588 — Cross-site Scripting in Fortinet | cvebase