FG-IR-23-485: Cross site scripting vulnerability in SSL VPN web UI
An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS and FortiProxy's web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via social engineering the targeted user into bookmarking a malicious samba server, then opening the bookmark.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-485?
The severity of FG-IR-23-485 is significant due to its potential for Cross-Site Scripting attacks.
How do I fix FG-IR-23-485?
To mitigate FG-IR-23-485, upgrade FortiOS or FortiProxy to the latest version listed in the advisory.
What are the affected versions for FG-IR-23-485?
FG-IR-23-485 affects specific versions of FortiOS and FortiProxy, specifically those prior to 7.4.4, 7.2.10, and 7.0.17.
Who is at risk from FG-IR-23-485?
Remote unauthenticated attackers can exploit FG-IR-23-485, putting users who bookmark malicious sites at risk.
What type of vulnerability is FG-IR-23-485?
FG-IR-23-485 is classified as an improper neutralization of input during web page generation vulnerability.