VYPR
Medium severity4.1NVD Advisory· Published Nov 2, 2021· Updated Jun 17, 2026

CVE-2020-12814

CVE-2020-12814

Description

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifically crafted requests to the web GUI.

Affected products

4
  • cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.6
    • cpe:2.3:a:fortinet:fortianalyzer:6.4.4:*:*:*:*:*:*:*
    • (no CPE)range: <=6.0.6, <=6.4.4
    • (no CPE)range: FortiAnalyzer 6.4.4, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.