← Vulnerability feed

Vulnerability record · CVE-2018-13380 · published 4 June 2019

CVE-2018-13380: Fortinet FortiOS and FortiProxy SSL VPN portal reflected XSS

Fortinet · Fortios

FortiOS (6.0.0-6.0.4, 5.6.0-5.6.7, 5.4.0-5.4.12, 5.2 and below) and FortiProxy (2.0.0, 1.2.8 and below) fail to properly neutralize input in the SSL VPN web portal's error and message handling parameters, allowing script injection. Because the portal is the entry point remote users authenticate through, a successful attack can run script in the context of a victim's authenticated session.

6.1 CVSS 3.1 Medium EPSS 62% · top 0.8% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS 6.1 medium with required user interaction, but the high EPSS percentile and internet-facing SSL VPN portal raise the practical risk.

What it is

FortiOS (6.0.0-6.0.4, 5.6.0-5.6.7, 5.4.0-5.4.12, 5.2 and below) and FortiProxy (2.0.0, 1.2.8 and below) fail to properly neutralize input in the SSL VPN web portal's error and message handling parameters, allowing script injection. Because the portal is the entry point remote users authenticate through, a successful attack can run script in the context of a victim's authenticated session.

Impact

An attacker can execute arbitrary script in a victim's browser within the SSL VPN portal origin, enabling session theft, credential capture, or actions performed as the logged-in user. The CVSS scope change (S:C) reflects that the impact can extend beyond the vulnerable component.

Attack surface

Reached over the network via the SSL VPN web portal; the CVSS vector shows no privileges required (PR:N) but user interaction is required (UI:R), meaning a victim must load a crafted link or page. No authentication is needed to deliver the payload, though the victim is typically an authenticated portal user.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware association is recorded in this data; EPSS is high at 0.62474 (99.1st percentile), indicating elevated predicted exploitation activity. References are vendor advisories only, with no exploit-tagged sources.

What to do

  • Upgrade FortiOS and FortiProxy to vendor-fixed versions per Fortinet advisories FG-IR-18-383 and FG-IR-20-230.
  • If immediate upgrade is not possible, apply the mitigations described in the vendor advisory and restrict SSL VPN portal exposure to trusted networks.
  • Enforce MFA and short session lifetimes on SSL VPN to limit the value of a stolen session.
  • Deploy a WAF or input-filtering rule to block script payloads in portal error and message parameters.
  • Review SSL VPN portal access logs for suspicious parameter values and unexpected client behavior.

Detection

  • Search web/proxy logs for script tags, event handlers, or encoded script sequences in SSL VPN portal error and message query parameters.
  • Monitor for anomalous SSL VPN portal requests containing reflected parameter values returned in responses.
  • Alert on unusual post-authentication portal activity from a single session, such as rapid configuration or credential-related actions.
  • Correlate portal access with outbound requests to unfamiliar domains that could indicate script exfiltration.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-13380 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed9.8CVE-2025-59718Fortinet FortiOS/FortiProxy SAML signature check bypass in FortiCloud SSOFortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An un…KEVEPSS 68%analysed9.8CVE-2024-55591FortiOS and FortiProxy authentication bypass via Node.js websocketFortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 contain an authentication bypass (CWE-288) reachable throug…KEVEPSS 94%analysed9.8CVE-2024-23113Fortinet FortiOS and related products format string remote code executionA use of externally-controlled format string (CWE-134) in Fortinet FortiOS, FortiProxy, FortiPAM and FortiSwitchManager lets an attacker execute unau…KEVEPSS 62%analysed9.8CVE-2024-21762Fortinet FortiOS and FortiProxy out-of-bounds write in SSL VPNFortiOS and FortiProxy contain an out-of-bounds write (CWE-787) reachable through specifically crafted requests. The flaw affects a wide range of For…KEVEPSS 83%analysed9.8CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN heap buffer overflowFortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow (CWE-122/CWE-787) reachable through specifically crafted requests. It is a pre-au…KEVEPSS 86%analysed9.8CVE-2022-42475FortiOS and FortiProxy SSL-VPN heap buffer overflow allows remote code executionA heap-based buffer overflow (CWE-122/CWE-787) in the FortiOS and FortiProxy SSL-VPN component lets a remote attacker trigger memory corruption throu…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2018-13380), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.