CVE Database
/

CVE-2018-1355

Back to search

CVE-2018-1355

Published: Jun 27, 2018

Modified: Oct 25, 2024

PUBLISHED

Description

An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.

VendorProductVersions

Fortinet, Inc.

Fortinet FortiManager, FortiAnalyzer

affected
FortiManager 6.0.0, 5.6.5 and below versions
affected
FortiAnalyzer 6.0.0, 5.6.5 and below versions

References

104546
vdb-entry
x_refsource_BID
1041185
vdb-entry
x_refsource_SECTRACK
1041184
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now