Loading HuntDB...

GHSA-ffmh-82q7-w4gf

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed while viewing the logs in FortiAnalyzer and FortiManager (with FortiAnalyzer feature enabled).

Related CVEs

Key Information

GHSA ID
GHSA-ffmh-82q7-w4gf
Published
May 24, 2022 4:46 PM
Last Modified
April 4, 2024 12:48 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.