An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-485 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
24 Jul 2025, 20:00
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fortinet fortiproxy
Fortinet fortios Fortinet |
|
Summary |
|
|
CPE | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-485 - Vendor Advisory |
14 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-14 10:15
Updated : 2025-07-24 20:00
NVD link : CVE-2024-26006
Mitre link : CVE-2024-26006
CVE.ORG link : CVE-2024-26006
JSON object : View
Products Affected
fortinet
- fortios
- fortiproxy
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')