High severity8.8NVD Advisory· Published Sep 24, 2020· Updated Jun 17, 2026
CVE-2020-12817
CVE-2020-12817
Description
An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.
Affected products
7cpe:2.3:a:fortinet:fortianalyzer:6.2.5:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:fortinet:fortianalyzer:6.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortianalyzer:6.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortianalyzer:6.4.1:*:*:*:*:*:*:*
- (no CPE)range: <6.4.1, <6.2.5
- (no CPE)range: FortiAnalyzer before 6.4.1; before 6.2.5
cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*range: <=3.7.0
- cpe:2.3:a:fortinet:fortitester:3.8.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-054nvdVendor Advisory
News mentions
0No linked articles in our index yet.