CVE-2018-1355: Fortinet Fortianalyzer

Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.

An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.

Affected products

  • Fortinet Fortianalyzer: up to and including 5.6.5; version 6.0.0 only
  • Fortinet FortiManager: up to and including 5.6.5; version 6.0.0 only

Published 2018-06-27. Last modified 2026-06-17.