Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-43081: Fortiguard

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

CVE
#xss#vulnerability#web#ios#auth

** PSIRT Advisories**

FortiProxy & FortiOS - XSS vulnerability in Web Filter Block Override Form

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiProxy and FortiOS web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

Affected Products

FortiOS version 7.0.3 and below,
FortiOS version 6.4.8 and below,
FortiOS version 6.2.10 and below,
FortiOS version 6.0.14 to 6.0.0.

FortiProxy version 7.0.1 and below,
FortiProxy version 2.0.7 to 2.0.0.

Solutions

Please upgrade to FortiProxy version 7.0.2 or above.
Please upgrade to FortiProxy version 2.0.8 or above.
Please upgrade to FortiOS version 7.0.4 or above.
Please upgrade to FortiOS version 6.4.9 or above.

Acknowledgement

Fortinet is pleased to thank Tom Tervoort for bringing this issue to our attention under responsible disclosure.

Related news

CVE-2021-43081: Fortiguard

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907