AnĀ improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.
2024-11-12T19:15:09.723
2025-01-17T20:35:31.247
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiproxy | < 7.0.17 | Yes |
Application | fortinet | fortiproxy | < 7.2.10 | Yes |
Application | fortinet | fortiproxy | < 7.4.4 | Yes |
Operating System | fortinet | fortios | < 7.2.9 | Yes |
Operating System | fortinet | fortios | < 7.4.4 | Yes |