QID 43983
Date Published: 2023-02-22
QID 43983: FortiOS Cross-Site Scripting (XSS) Vulnerability (FG-IR-22-224)
An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.7
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-224 Workaround:
Disable "Sign in with FortiCloud" feature using the below command config system global set admin-forticloud-sso-login disable end
Disable "Sign in with FortiCloud" feature using the below command config system global set admin-forticloud-sso-login disable end
Vendor References
- FG-IR-22-224 -
www.fortiguard.com/psirt/FG-IR-22-224
CVEs related to QID 43983
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-224 |
|