Fortinet FortiManager and FortiAnalyzer "tabview.htm" Cross-Site Scripting Vulnerability
Description
(:A client-side cross-site scripting vulnerability was reported in Fortinet FortiManager and FortiAnalyzer.:An authenticated remote attacker could exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript/HTML code.::This vulnerability is located in the "tabs" and "urls" parameters of the "/cgi-bin/module/docroot/tabview.htm" web page.::Proofs of concept are available.)