CVE-2018-13380 is a Cross-site Scripting (XSS) vulnerability affecting Fortinet FortiOS and FortiProxy products, specifically within their SSL VPN web portal. This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated attacker to execute malicious script code by manipulating error or message handling parameters, potentially leading to information disclosure or defacement. While there is no evidence of active exploitation in the wild (KEV), public exploit templates exist for Nuclei, and its EPSS score indicates a higher than average probability of exploitation. Despite this, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 5.4.0, <= 5.4.12CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 5.6.0, <= 5.6.7CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 6.0.0, <= 6.0.4CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
<= 1.2.8CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.