Fortinet FortiManager Cross-Site Scripting Vulnerability Fixed by 5.0.12, 5.2.6 and 5.4.1
Description
(:A cross-site scripting vulnerability was reported in Fortinet FortiManager.:An authenticated remote attacker could exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.::This vulnerability is located in Predefined Bookmarks' name and description parameters of the "Policy & Objects > Security Profiles > SSL VPN Portal" page.::A proof of concept is available.)