CVE-2023-37933

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP or HTTPs requests.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-23-216 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:7.4.0:*:*:*:*:*:*:*

History

22 Jul 2025, 21:39

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortiadc:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
References () https://fortiguard.com/psirt/FG-IR-23-216 - () https://fortiguard.com/psirt/FG-IR-23-216 - Vendor Advisory
Summary
  • (es) Una vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web ('Cross-site Scripting') [CWE-79] en la GUI de FortiADC versión 7.4.0, 7.2.0 a 7.2.1 y anteriores a 7.1.3 permite que un atacante autenticado realice un ataque XSS a través de solicitudes HTTP o HTTPS manipuladas.
First Time Fortinet
Fortinet fortiadc

11 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 15:15

Updated : 2025-07-22 21:39


NVD link : CVE-2023-37933

Mitre link : CVE-2023-37933

CVE.ORG link : CVE-2023-37933


JSON object : View

Products Affected

fortinet

  • fortiadc
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')