.. / CVE-2018-13380

Exploit for Fortinet FortiOS - Cross-Site Scripting (CVE-2018-13380)

Description:

Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below versions under SSL VPN web portal are vulnerable to cross-site scripting and allows attacker to execute unauthorized malicious script code via the error or message handling parameters.

Nuclei Template

View the template here CVE-2018-13380.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-13380.yaml
Copy

References:

https://fortiguard.com/advisory/FG-IR-20-230
https://nvd.nist.gov/vuln/detail/CVE-2018-13380
https://fortiguard.com/advisory/FG-IR-18-383
https://blog.orange.tw/2019/08/attacking-ssl-vpn-part-2-breaking-the-fortigate-ssl-vpn.html
https://github.com/merlinepedra25/nuclei-templates