CVE-2023-36555: FortiOS - HTML injection in SAML and Security Fabric components
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.
Other sources
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiOS may allow a remote authenticated attacker to inject script related HTML tags via the SAML and Security Fabric components.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
CVE-2023-36555
What is the severity of CVE-2023-36555?
The severity of CVE-2023-36555 is medium with a CVSS score of 5.4.
What is the affected software for CVE-2023-36555?
The affected software for CVE-2023-36555 is Fortinet FortiOS version 7.2.0 - 7.2.4.
How can an attacker exploit CVE-2023-36555?
An attacker can exploit CVE-2023-36555 by executing unauthorized code or commands via the SAML and Security Fabric components.
Is there a fix available for CVE-2023-36555?
Yes, Fortinet has released a fix for CVE-2023-36555. It is recommended to upgrade to the latest version of Fortinet FortiOS.