QID 44036
Date Published: 2023-05-31
QID 44036: FortiOS Cross-Site Scripting (XSS) Vulnerability in Web Filter Block Override Form (FG-IR-21-230) (Unauthenticated Check)
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiProxy and FortiOS web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Affected Products:
FortiOS version 7.0.3 and below
FortiOS version 6.4.8 and below
FortiOS version 6.2.10 and below
FortiOS version 6.0.14 to 6.0.0
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable FortiOS may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-230
Vendor References
- FG-IR-21-230 -
www.fortiguard.com/psirt/FG-IR-21-230
CVEs related to QID 44036
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-230 |
|