Medium severity4.1NVD Advisory· Published Nov 2, 2021· Updated Jun 17, 2026
CVE-2020-12814
CVE-2020-12814
Description
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifically crafted requests to the web GUI.
Affected products
4cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.6
- cpe:2.3:a:fortinet:fortianalyzer:6.4.4:*:*:*:*:*:*:*
- (no CPE)range: <=6.0.6, <=6.4.4
- (no CPE)range: FortiAnalyzer 6.4.4, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-092nvdBroken LinkVendor Advisory
News mentions
0No linked articles in our index yet.