Medium severity6.1NVD Advisory· Published Sep 24, 2020· Updated Jun 17, 2026
CVE-2020-12811
CVE-2020-12811
Description
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name field.
Affected products
5cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >=6.2.0,<=6.2.6
- (no CPE)range: 6.2.0, 6.2.1, 6.2.2, and 6.2.3
- (no CPE)range: FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3 ; FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: >=6.2.0,<=6.2.6
- (no CPE)range: 6.2.0, 6.2.1, 6.2.2, and 6.2.3
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-005nvdVendor Advisory
News mentions
0No linked articles in our index yet.