An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially crafted lure resource ID.
2022-11-02T12:15:54.067
2024-11-21T07:16:20.723
Modified
CVSSv3.1: 8.0 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortideceptor | 4.0.2 | Yes |
Application | fortinet | fortideceptor | 4.1.0 | Yes |
Application | fortinet | fortideceptor | 4.1.1 | Yes |
Application | fortinet | fortideceptor | 4.2.0 | Yes |