VYPR
Medium severity6.1NVD Advisory· Published Jun 4, 2019· Updated Jun 17, 2026

CVE-2019-5586

CVE-2019-5586

Description

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "param" parameter of the error process HTTP requests.

Affected products

3
  • Fortinet/Fortios2 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=5.2.0,<=6.0.4
    • (no CPE)range: 5.2.0 to 5.6.10, 6.0.0 to 6.0.4
  • Fortinet/Fortinetcpe-rescue
    Range: FortiOS 5.2.0 to 6.0.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.