Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29183


An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting.


Published

2023-09-13T13:15:08.367

Last Modified

2024-11-21T07:56:40.483

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiproxy < 7.0.11 Yes
Application fortinet fortiproxy < 7.2.5 Yes
Operating System fortinet fortios < 6.2.15 Yes
Operating System fortinet fortios < 6.4.13 Yes
Operating System fortinet fortios < 7.0.12 Yes
Operating System fortinet fortios < 7.2.5 Yes

References