QID 44032
Date Published: 2023-05-31
QID 44032: FortiOS - Stored Cross-Site Scripting (XSS) Vulnerability (FG-IR-21-248) (Unauthenticated Check)
A improper neutralization of input during web page generation (cross-site scripting) [CWE-79] in FortiOS may allow a privileged attacker to perform a stored XSS attack via storing malicious payloads in replacement messages.
Affected Versions:
FortiOS version 7.0.0 through 7.0.3
FortiOS version 6.4.0 through 6.4.9
FortiOS version 6.2.2 through 6.2.12
FortiOS version 6.0.7 through 6.0.15
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow a privileged attacker to perform a stored XSS attack via storing malicious payloads in replacement messages.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-21-248
Vendor References
- FG-IR-21-248 -
www.fortiguard.com/psirt/FG-IR-21-248
CVEs related to QID 44032
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-248 |
|