An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform a reflected cross site scripting (XSS) via crafted HTTP requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | CHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | LOW |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-79
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| fortinet | fortios | * | <built-in method update of dict object at 0x7d1e643c3f40> | Operating System |
| fortinet | fortios | * | <built-in method update of dict object at 0x7d1e542c4e80> | Operating System |
| fortinet | fortiproxy | * | <built-in method update of dict object at 0x7d1e643c1740> | Application |
| fortinet | fortisase | 25.3.40 | <built-in method update of dict object at 0x7d1e6dc388c0> | Application |
| fortinet | fortisase | 25.3.40 | <built-in method update of dict object at 0x7d1e643c1300> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:feature:*:*:* |
| Yes | cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:mature:*:*:* |