← All CVEs

CVE-2018-13380

medium · 4.7

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.

4.7
CVSS
62.5%
EPSS (exploit prob.)
99th
EPSS percentile
2019-06-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
fortinetfortios<= 5.2
fortinetfortios>= 5.4.0, <= 5.4.12
fortinetfortios>= 5.6.0, <= 5.6.7
fortinetfortios>= 6.0.0, <= 6.0.4
fortinetfortiproxy<= 1.2.8
fortinetfortiproxy2.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-13380