First published: Tue Jun 11 2024(Updated: )
An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS and FortiProxy reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=7.4.0<=7.4.3 | |
Fortinet FortiOS | >=7.2.0<=7.2.7 | |
Fortinet FortiOS | >=7.0.0<=7.0.13 | |
Fortinet FortiProxy | >=7.4.0<=7.4.2 | |
Fortinet FortiProxy | >=7.2.0<=7.2.8 | |
Fortinet FortiProxy | >=7.0.0<=7.0.14 | |
Fortinet FortiProxy | >=7.0.0<7.0.15 | |
Fortinet FortiProxy | >=7.2.0<7.2.9 | |
Fortinet FortiProxy | >=7.4.0<7.4.3 | |
Fortinet FortiOS | >=7.0.0<7.0.14 | |
Fortinet FortiOS | >=7.2.0<7.2.8 | |
Fortinet FortiOS | >=7.4.0<7.4.4 |
Please upgrade to FortiOS version 7.4.4 or above Please upgrade to FortiOS version 7.2.8 or above Please upgrade to FortiOS version 7.0.14 or above Please upgrade to FortiProxy version 7.4.3 or above Please upgrade to FortiProxy version 7.2.9 or above Please upgrade to FortiProxy version 7.0.15 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.