VYPR
High severity8.8NVD Advisory· Published Sep 24, 2020· Updated Jun 17, 2026

CVE-2020-12817

CVE-2020-12817

Description

An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.

Affected products

7
  • cpe:2.3:a:fortinet:fortianalyzer:6.2.5:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:fortinet:fortianalyzer:6.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortianalyzer:6.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortianalyzer:6.4.1:*:*:*:*:*:*:*
    • (no CPE)range: <6.4.1, <6.2.5
    • (no CPE)range: FortiAnalyzer before 6.4.1; before 6.2.5
  • cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*range: <=3.7.0
    • cpe:2.3:a:fortinet:fortitester:3.8.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.