FG-IR-23-106: Stored XSS in guest management page
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS and FortiProxy GUI may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-106?
The FG-IR-23-106 vulnerability is classified as a moderate severity Cross-site Scripting (XSS) issue.
How do I fix FG-IR-23-106?
To fix FG-IR-23-106, upgrade FortiOS or FortiProxy to the specified remedial versions: FortiOS 7.2.5, 7.0.12, 6.4.13, 6.2.15, or FortiProxy 7.2.5 and 7.0.11.
Which versions are affected by FG-IR-23-106?
FG-IR-23-106 affects FortiOS versions from 6.2.0 to 7.2.4 and FortiProxy versions from 7.0.0 to 7.2.4.
What systems are impacted by FG-IR-23-106?
The systems impacted by FG-IR-23-106 include FortiOS and FortiProxy web GUI interfaces.
Who can exploit FG-IR-23-106?
An authenticated attacker can exploit FG-IR-23-106 to execute malicious JavaScript code through crafted guest management settings.