Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below versions under SSL VPN web portal are vulnerable to cross-site scripting and allows attacker to execute unauthorized malicious script code via the error or message handling parameters.
id: CVE-2018-13380
info:
name: Fortinet FortiOS - Cross-Site Scripting
author: shelld3v,AaronCh
...