QID 44008
Date Published: 2023-04-13
QID 44008: Fortinet FortiOS Cross-Site Scripting (XSS) Vulnerability (FG-IR-22-363)
Multiple improper sanitization of user input during web page generation leads to Cross-site Scripting vulnerabilities in FortiOS administrative interface.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
FortiOS version 6.4.0 through 6.4.11
FortiOS version 6.2.0 through 6.2.12
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP or HTTPS GET requests.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-363
Vendor References
- FG-IR-22-363 -
www.fortiguard.com/psirt/FG-IR-22-363
CVEs related to QID 44008
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-363 |
|