Open redirect in FortiOS - CVE-2017-14186
Published: December 1, 2017 / Updated: May 27, 2019
Vulnerability details
Vulnerability allows a remote authenticated attacker to perform open redirection attacks.
The vulnerability is caused by an input validation error in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.6, 5.2.0 to 5.2.12, 5.0 and below versions under SSL VPN web portal when processing the login "redir" parameter. A remote attacker can redirect users to an external website.