An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
2022-07-18T18:15:08.963
2024-11-21T06:48:33.510
Modified
CVSSv3.1: 4.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fortinet | fortios | ≤ 6.4.9 | Yes |
Operating System | fortinet | fortios | ≤ 7.0.5 | Yes |