An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-485 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
24 Jul 2025, 20:00
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-485 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
First Time |
Fortinet fortiproxy
Fortinet Fortinet fortios |
14 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-14 10:15
Updated : 2025-07-24 20:00
NVD link : CVE-2024-26006
Mitre link : CVE-2024-26006
JSON object : View
Products Affected
fortinet
- fortiproxy
- fortios
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')