CVE-2023-29183: Stored XSS in guest management page
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS and FortiProxy GUI may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting.
Other sources
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2023-29183.
What is the severity of CVE-2023-29183?
The severity of CVE-2023-29183 is high.
Which software versions are affected by CVE-2023-29183?
FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, and FortiOS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.13, and 6.2.0 through 6.2.15 are affected by CVE-2023-29183.
What is the CWE-ID associated with CVE-2023-29183?
The CWE-ID associated with CVE-2023-29183 is CWE-79.
How can I fix the CVE-2023-29183 vulnerability?
To fix the CVE-2023-29183 vulnerability, it is recommended to update FortiProxy and FortiOS to the latest versions available, as the issue has been patched in later releases.