QID 44090
Date Published: 2023-07-14
QID 44090: Fortinet FortiOS Host Header Injection Vulnerability (FG-IR-19-301)
An improper neutralization of input during web page generation vulnerability [CWE-79]A in FortiOSA may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript codeA in the victim's browser context. This happens when the FortiGate has web filtering and category override enabled/configured.
Affected Versions:
FortiOS version 6.4.0 through 6.4.1
FortiOS version 6.2.0 through 6.2.9
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Note: Making this QID practice as this QID also contains banner based detection .
Successful exploitation of the vulnerability may allow authenticated remote attacker to perform a Host header injection vulnerability
- FG-IR-19-301 -
www.fortiguard.com/psirt/FG-IR-19-301
CVEs related to QID 44090
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-19-301 |
|