CVE-2023-37933: XSS
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP or HTTPs requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37933?
CVE-2023-37933 has a medium severity rating, as it allows authenticated attackers to execute Cross-site Scripting (XSS) attacks.
How do I fix CVE-2023-37933?
To fix CVE-2023-37933, upgrade your FortiADC GUI to version 7.4.0 or apply the necessary patches recommended by Fortinet.
Who is affected by CVE-2023-37933?
Users of Fortinet FortiADC GUI versions 7.2.0 through 7.2.1 and below version 7.1.3 are affected by CVE-2023-37933.
What type of vulnerability is CVE-2023-37933?
CVE-2023-37933 is classified as a Cross-site Scripting (XSS) vulnerability due to improper input neutralization on web page generation.
Can CVE-2023-37933 be exploited remotely?
Yes, CVE-2023-37933 can be exploited remotely by authenticated attackers through crafted HTTP or HTTPS requests.