CVE-2019-16151Cross-site Scripting in Fortinet Fortios

Severity
6.1MEDIUMNVD
CNA4.7
EPSS
0.1%
top 71.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 21

Description

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context. This happens when the FortiGate has web filtering and category override enabled/configured.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDfortinet/fortios6.2.06.2.10+1
CVEListV5fortinet/fortios6.4.06.4.1+1

🔴Vulnerability Details

2
CVEList
CVE-2019-16151: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 62025-03-21
GHSA
GHSA-c55x-8r3h-3586: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 62025-03-21

📋Vendor Advisories

1
Fortinet
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9...2025-03-21
CVE-2019-16151 — Cross-site Scripting in Fortinet | cvebase