An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-23-106 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-09-13 13:15
Updated : 2023-11-07 04:11
NVD link : CVE-2023-29183
Mitre link : CVE-2023-29183
CVE.ORG link : CVE-2023-29183
JSON object : View
Products Affected
fortinet
- fortiproxy
- fortios
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')