Medium severity5.4NVD Advisory· Published Jun 4, 2020· Updated Jun 17, 2026
CVE-2020-6640
CVE-2020-6640
Description
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.
Affected products
3cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: <6.2.4
- (no CPE)
- Fortinet/FortiAnalyzerdescription
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-003nvdVendor Advisory
News mentions
0No linked articles in our index yet.