An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-471 | Vendor Advisory |
https://fortiguard.fortinet.com/psirt/FG-IR-23-471 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-06-11 15:16
Updated : 2024-11-21 08:56
NVD link : CVE-2024-23111
Mitre link : CVE-2024-23111
CVE.ORG link : CVE-2024-23111
JSON object : View
Products Affected
fortinet
- fortiproxy
- fortios
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')