CVE-2024-35280: XSS
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions, FortiDeceptor 4.0 all versions, FortiDeceptor 3.3 all versions, FortiDeceptor 3.2 all versions, FortiDeceptor 3.1 all versions, FortiDeceptor 3.0 all versions may allow an attacker to perform a reflected cross-site scripting attack in the recovery endpoints
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35280?
CVE-2024-35280 is classified as a high severity vulnerability due to its potential impact on user data and security.
How do I fix CVE-2024-35280?
To fix CVE-2024-35280, update Fortinet FortiDeceptor to the latest version that contains the security patches.
What systems are affected by CVE-2024-35280?
CVE-2024-35280 affects all versions of Fortinet FortiDeceptor from 3.x to 5.3.0 inclusive.
What type of vulnerability is CVE-2024-35280?
CVE-2024-35280 is a cross-site scripting (XSS) vulnerability that allows for reflected attacks.
What could an attacker achieve with CVE-2024-35280?
An attacker exploiting CVE-2024-35280 could execute malicious scripts in the context of users' browsers, potentially stealing sensitive information.