CVE-2020-12817: Fortinet Fortianalyzer
High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.
An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.
Affected products
- Fortinet Fortianalyzer: version 6.2.5 only; version 6.4.0 only; version 6.4.1 only
- Fortinet Fortitester: up to and including 3.7.0; version 3.8.0 only
Published 2020-09-24. Last modified 2026-06-17.