Vulnerability record · CVE-2018-13380 · published 4 June 2019
CVE-2018-13380: Fortinet FortiOS and FortiProxy SSL VPN portal reflected XSS
Fortinet · Fortios
FortiOS (6.0.0-6.0.4, 5.6.0-5.6.7, 5.4.0-5.4.12, 5.2 and below) and FortiProxy (2.0.0, 1.2.8 and below) fail to properly neutralize input in the SSL VPN web portal's error and message handling parameters, allowing script injection. Because the portal is the entry point remote users authenticate through, a successful attack can run script in the context of a victim's authenticated session.
Description
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS 6.1 medium with required user interaction, but the high EPSS percentile and internet-facing SSL VPN portal raise the practical risk.
What it is
FortiOS (6.0.0-6.0.4, 5.6.0-5.6.7, 5.4.0-5.4.12, 5.2 and below) and FortiProxy (2.0.0, 1.2.8 and below) fail to properly neutralize input in the SSL VPN web portal's error and message handling parameters, allowing script injection. Because the portal is the entry point remote users authenticate through, a successful attack can run script in the context of a victim's authenticated session.
Impact
An attacker can execute arbitrary script in a victim's browser within the SSL VPN portal origin, enabling session theft, credential capture, or actions performed as the logged-in user. The CVSS scope change (S:C) reflects that the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via the SSL VPN web portal; the CVSS vector shows no privileges required (PR:N) but user interaction is required (UI:R), meaning a victim must load a crafted link or page. No authentication is needed to deliver the payload, though the victim is typically an authenticated portal user.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware association is recorded in this data; EPSS is high at 0.62474 (99.1st percentile), indicating elevated predicted exploitation activity. References are vendor advisories only, with no exploit-tagged sources.
What to do
- Upgrade FortiOS and FortiProxy to vendor-fixed versions per Fortinet advisories FG-IR-18-383 and FG-IR-20-230.
- If immediate upgrade is not possible, apply the mitigations described in the vendor advisory and restrict SSL VPN portal exposure to trusted networks.
- Enforce MFA and short session lifetimes on SSL VPN to limit the value of a stolen session.
- Deploy a WAF or input-filtering rule to block script payloads in portal error and message parameters.
- Review SSL VPN portal access logs for suspicious parameter values and unexpected client behavior.
Detection
- Search web/proxy logs for script tags, event handlers, or encoded script sequences in SSL VPN portal error and message query parameters.
- Monitor for anomalous SSL VPN portal requests containing reflected parameter values returned in responses.
- Alert on unusual post-authentication portal activity from a single session, such as rapid configuration or credential-related actions.
- Correlate portal access with outbound requests to unfamiliar domains that could indicate script exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/advisory/FG-IR-18-383 | MitigationVendor Advisory |
| https://fortiguard.com/advisory/FG-IR-20-230 | Vendor Advisory |
| https://fortiguard.com/advisory/FG-IR-18-383 | MitigationVendor Advisory |
| https://fortiguard.com/advisory/FG-IR-20-230 | Vendor Advisory |
Track CVE-2018-13380 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-13380), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.