CVE-2019-6697Cross-site Scripting in Fortinet Fortios

Severity
6.1MEDIUMNVD
CNA5.3
EPSS
0.1%
top 71.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 17

Description

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate to perform a Stored Cross Site Scripting attack (XSS) by sending a crafted DHCP packet.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDfortinet/fortios6.0.06.0.7+1
CVEListV5fortinet/fortios6.2.06.2.1

🔴Vulnerability Details

2
GHSA
GHSA-fwm7-53g9-cmxr: An Improper Neutralization of Input vulnerability affecting FortiGate version 62025-03-17
CVEList
CVE-2019-6697: An Improper Neutralization of Input vulnerability affecting FortiGate version 62025-03-17

📋Vendor Advisories

1
Fortinet
An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 i...2025-03-17
CVE-2019-6697 — Cross-site Scripting in Fortinet | cvebase