First published: Tue Apr 11 2023(Updated: )
A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiOS and FortiProxy sslvpnd may allow an authenticated attacker to redirect users to any arbitrary website via a crafted URL.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | ||
Fortinet FortiProxy |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-22-479 is classified as high due to its potential for abuse in redirecting users to malicious websites.
To fix FG-IR-22-479, apply the latest security patches provided by Fortinet for FortiOS and FortiProxy.
FG-IR-22-479 affects users of Fortinet FortiOS and FortiProxy versions vulnerable to the open redirect vulnerability.
FG-IR-22-479 is classified as a URL redirection to an untrusted site or 'Open Redirect' vulnerability.
Yes, FG-IR-22-479 can be exploited by authenticated attackers to redirect users to arbitrary websites.