CVE-2024-23111: FortiOS/FortiProxy - XSS in reboot page
An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS and FortiProxy reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.
Other sources
An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23111?
CVE-2024-23111 is categorized as a high severity vulnerability due to the potential for remote code execution by privileged attackers.
How do I fix CVE-2024-23111?
To fix CVE-2024-23111, upgrade FortiOS to version 7.4.4 or higher, 7.2.8 or higher, or 7.0.14 or higher, or update FortiProxy to version 7.4.3 or higher, 7.2.9 or higher, or 7.0.15 or higher.
What products are affected by CVE-2024-23111?
CVE-2024-23111 affects FortiOS versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.7, and 7.0.0 to 7.0.13, as well as FortiProxy versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.8, and 7.0.0 to 7.0.14.
What types of attacks can exploit CVE-2024-23111?
CVE-2024-23111 can be exploited through crafted HTTP GET requests, allowing attackers to execute arbitrary JavaScript in the context of an affected web page.
Who can exploit CVE-2024-23111?
CVE-2024-23111 can be exploited by remote attackers with super-admin access to the affected FortiOS or FortiProxy devices.