An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: fortinet
Published: 2018-06-27T20:00:00Z
Updated: 2024-10-25T14:09:11.290Z
Reserved: 2017-12-11T00:00:00
Link: CVE-2018-1355
Vulnrichment
Updated: 2024-08-05T03:59:38.991Z
NVD
Status : Modified
Published: 2018-06-27T20:29:04.933
Modified: 2024-11-21T03:59:41.097
Link: CVE-2018-1355
Redhat
No data.