Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-26006


An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.


Published

2025-03-14T10:15:14.520

Last Modified

2025-07-24T20:00:45.110

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System fortinet fortios < 7.0.14 Yes
Operating System fortinet fortios < 7.2.8 Yes
Operating System fortinet fortios < 7.4.4 Yes
Application fortinet fortiproxy < 7.0.17 Yes
Application fortinet fortiproxy < 7.2.10 Yes
Application fortinet fortiproxy < 7.4.4 Yes

References