A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.
https://www.exploit-db.com/exploits/42388/
https://fortiguard.com/advisory/FG-IR-17-104