CVE-2024-26006Cross-site Scripting in Fortinet Fortios

Severity
6.1MEDIUMNVD
CNA7.5
EPSS
0.5%
top 32.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14

Description

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDfortinet/fortios6.4.07.0.14+2
NVDfortinet/fortiproxy7.0.07.0.17+2
CVEListV5fortinet/fortios7.4.07.4.3+3
CVEListV5fortinet/fortiproxy7.4.07.4.3+2

🔴Vulnerability Details

2
CVEList
CVE-2024-26006: An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 72025-03-14
GHSA
GHSA-4678-x95m-c2hf: An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 72025-03-14

📋Vendor Advisories

1
Fortinet
Cross site scripting vulnerability in SSL VPN web UI2025-03-14
CVE-2024-26006 — Cross-site Scripting in Fortinet | cvebase