An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | CHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | LOW |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-79
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| fortinet | fortiproxy | * | <built-in method update of dict object at 0x72f059927600> | Application |
| fortinet | fortiproxy | * | <built-in method update of dict object at 0x72f059925980> | Application |
| fortinet | fortios | * | <built-in method update of dict object at 0x72efbdb0bcc0> | Operating System |
| fortinet | fortipam | * | <built-in method update of dict object at 0x72f0592d7080> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* |