QID 44103
Date Published: 2023-10-17
QID 44103: FortiOS HTML injection Vulnerability (FG-IR-23-104)
CVE-2023-36555: An improper neutralization of script-related HTML tags in a web page vulnerability in FortiOS.
Affected Versions:
FortiOS version 7.2.0 through 7.2.4
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Successful exploitation of this vulnerability may allow a remote authenticated attacker to inject script related HTML tags via the SAML and Security Fabric components.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-23-104
Vendor References
- FG-IR-23-104 -
www.fortiguard.com/psirt/FG-IR-23-104
CVEs related to QID 44103
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-104 |
|