An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.
History

Fri, 23 Aug 2024 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet
Fortinet fortios
Fortinet fortiproxy
CPEs cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortios
Fortinet fortiproxy

Mon, 19 Aug 2024 05:30:00 +0000

Type Values Removed Values Added
Description An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests. An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2024-06-11T14:32:00.312Z

Updated: 2024-08-19T05:18:38.679Z

Reserved: 2024-01-11T16:29:07.979Z

Link: CVE-2024-23111

cve-icon Vulnrichment

Updated: 2024-08-01T22:51:11.306Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-11T15:16:03.957

Modified: 2024-08-23T02:47:13.560

Link: CVE-2024-23111

cve-icon Redhat

No data.