Medium severity6.1NVD Advisory· Published Aug 28, 2019· Updated Jun 17, 2026
CVE-2019-5590
CVE-2019-5590
Description
The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form.
Affected products
3Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/108786nvdThird Party AdvisoryVDB Entry
- fortiguard.com/advisory/FG-IR-19-070nvdVendor Advisory
News mentions
0No linked articles in our index yet.