First published: Tue Nov 12 2024(Updated: )
An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS and FortiProxy SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=7.4.0<=7.4.3 | |
Fortinet FortiOS | >=7.2.0<=7.2.8 | |
Fortinet FortiOS | >=7.0 | |
Fortinet FortiProxy | >=7.4.0<=7.4.3 | |
Fortinet FortiProxy | >=7.2.0<=7.2.9 | |
Fortinet FortiProxy | >=7.0.0<=7.0.16 |
Please upgrade to FortiOS version 7.6.0 or above Please upgrade to FortiProxy version 7.4.4 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.