CVE-2024-23111
CVE-2024-23111
6.8
MediumPublished:
Last updated:
Source:psirt@fortinet.com
Modified
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- Required
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.
References
psirt@fortinet.com
https://fortiguard.fortinet.com/psirt/FG-IR-23-471af854a3a-2127-422b-91ae-364da2661108
https://fortiguard.fortinet.com/psirt/FG-IR-23-471