CVE-2018-1355
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature.
Does this matter?
Lower severity and a low EPSS score (1.62%). Track it; it rarely justifies an emergency change on its own.
Description
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.62% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- fortinet/fortianalyzer · fortinet/fortimanager
- Source
- psirt@fortinet.com
References
- http://www.securityfocus.com/bid/104546Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041184Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041185Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-18-022Vendor Advisory
- http://www.securityfocus.com/bid/104546Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041184Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041185Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-18-022Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.