QID 43913

Date Published: 2022-10-17

QID 43913: FortiOS Cross-Site Scripting (XSS) Vulnerability (FG-IR-21-057)

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.

Affected Products:
FortiOS version 7.0.0 through 7.0.5
FortiOS version 6.4.0 through 6.4.9

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Vulnerable version of FortiOS may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-21-057

    Vendor References

    CVEs related to QID 43913

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-057 URL Logo www.fortiguard.com/psirt/FG-IR-21-057