CVE Published: 27/06/2018 |
CVE Updated: 25/10/2024 |
CVE Year: 2018 Source: fortinet |
Vendor: Fortinet, Inc. |
Product: Fortinet FortiManager, FortiAnalyzer Status : PUBLISHED
CVE-2018-1355 Description
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.