CVE-2018-1355 Information
Feb 14, 2021
cve
Description
An open redirect vulnerability in Fortinet FortiManager 6.0.0 5.6.5 and below versions FortiAnalyzer 6.0.0 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
http://www.securityfocus.com/bid/104546 http://www.securitytracker.com/id/1041184 http://www.securitytracker.com/id/1041185 https://fortiguard.com/advisory/FG-IR-18-022
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: