CVE-2024-26006: Cross site scripting vulnerability in SSL VPN web UI
An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS and FortiProxy's web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via social engineering the targeted user into bookmarking a malicious samba server, then opening the bookmark.
Other sources
An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26006?
CVE-2024-26006 is classified as a moderate severity vulnerability due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2024-26006?
To fix CVE-2024-26006, update FortiOS or FortiProxy to the latest versions, specifically 7.4.4 or later for affected versions.
Which versions of FortiOS are affected by CVE-2024-26006?
CVE-2024-26006 affects FortiOS versions 7.0.0 to 7.4.3, as well as 6.4.
Which versions of FortiProxy are affected by CVE-2024-26006?
CVE-2024-26006 affects FortiProxy versions 7.0.0 to 7.4.3.
What type of attack does CVE-2024-26006 allow?
CVE-2024-26006 allows a remote unauthenticated attacker to perform a Cross-Site Scripting (XSS) attack.