CVE-2020-6647

Severity
5.4MEDIUM
EPSS
0.4%
top 42.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 7
Latest updateMay 24

Description

An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5fortinet_fortiadcFortiADC 5.4.0 and 5.3.x before 5.3.5.

🔴Vulnerability Details

2
GHSA
GHSA-g9g7-5v3p-474j: An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting a2022-05-24
CVEList
CVE-2020-6647: An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting a2020-04-07

📋Vendor Advisories

1
Fortinet
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to pe...2020-04-07
CVE-2020-6647 (MEDIUM CVSS 5.4) | An improper neutralization of input | cvebase.io