← Back to browse · API

CVE-2018-13380

Severity
MEDIUM
CVSS
4.7
EPSS
0.62474
Risk score
40.67
CISA KEV
No
PoC
No
Published
2019-06-04
Modified
2024-10-25
First seen
2026-08-07
Aliases
EUVD-2018-5324, GHSA-P6VG-VJ3X-M483
Products
Fortinet:Fortinet FortiOS and FortiProxy FortiGate 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4.0 through 5.4.12, 5.2 and earlier and FortiProxy versions 2.0.0, 1.2.8 and earlier
Sources
euvd EUVD-2018-5324

Description

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.

References