CVE-2018-13380
medium · 4.7A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.
4.7
CVSS
62.5%
EPSS (exploit prob.)
99th
EPSS percentile
2019-06-04
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fortinet | fortios | <= 5.2 |
| fortinet | fortios | >= 5.4.0, <= 5.4.12 |
| fortinet | fortios | >= 5.6.0, <= 5.6.7 |
| fortinet | fortios | >= 6.0.0, <= 6.0.4 |
| fortinet | fortiproxy | <= 1.2.8 |
| fortinet | fortiproxy | 2.0.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-13380