QID 44112
Date Published: 2023-10-30
QID 44112: FortiOS Cross-Site Scripting (XSS) Vulnerability (FG-IR-19-184)
An Improper Neutralization of Input vulnerability in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate to perform a Stored Cross Site Scripting attack (XSS) by sending a crafted DHCP packet.
Affected Versions:
FortiOS version 6.2.1 and below
FortiOS version 6.0.6 and below
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Successful exploit may allow an authenticated attacker to execute unauthorized code or commands
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-19-184
- FG-IR-19-184 -
www.fortiguard.com/psirt/FG-IR-19-184
CVEs related to QID 44112
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-19-184 |
|