An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
2023-04-11T17:15:07.390
2024-11-21T07:23:04.087
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiproxy | < 7.0.8 | Yes |
Application | fortinet | fortiproxy | < 7.2.2 | Yes |
Operating System | fortinet | fortios | < 6.2.13 | Yes |
Operating System | fortinet | fortios | < 6.4.12 | Yes |
Operating System | fortinet | fortios | < 7.0.10 | Yes |
Operating System | fortinet | fortios | < 7.2.4 | Yes |