An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortiproxy | — | Upgrade FortiProxy to 7.0.15Upgrade FortiProxy to 7.2.9Upgrade FortiProxy to 7.4.3Upgrade to the latest version of FortiProxy | Sep 30, 2026 | Jun 11, 2024 |
| Fortios | — | Upgrade FortiOS to 7.2.8Upgrade FortiOS to 7.0.14Upgrade FortiOS to 7.4.4 | Aug 26, 2024 | Jun 11, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub