CVE-2019-5590: Fortinet FortiWeb
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form.
Affected products
- Fortinet FortiWeb: up to and including 6.0.2
Published 2019-08-28. Last modified 2026-06-17.