CVE-2018-13375

MEDIUM

Fortinet FortiAnalyzer and FortiManager < 5.6.0 - Stored Cross-Site Scripting via DHCP HOSTNAME Parameter

Title source: llm
STIX 2.1

Description

An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed while viewing the logs in FortiAnalyzer and FortiManager (with FortiAnalyzer feature enabled).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-18-121

Scores

CVSS v3 6.1
EPSS 0.0030
EPSS Percentile 53.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
fortinet/fortianalyzer < 5.6.0
fortinet/fortimanager < 5.6.0
Published May 28, 2019
Tracked Since Feb 18, 2026