CVE-2019-5586: Fortinet FortiOS
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "param" parameter of the error process HTTP requests.
Affected products
- Fortinet FortiOS: from 5.2.0, up to and including 6.0.4
Published 2019-06-04. Last modified 2026-06-17.