CVE-2024-35280Cross-site Scripting in Fortinet Fortideceptor

Severity
6.1MEDIUMNVD
CNA5.4
EPSS
0.7%
top 28.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 15

Description

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions, FortiDeceptor 4.0 all versions, FortiDeceptor 3.3 all versions, FortiDeceptor 3.2 all versions, FortiDeceptor 3.1 all versions, FortiDeceptor 3.0 all versions may allow an attacker to p

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDfortinet/fortideceptor3.0.05.2.1+1
CVEListV5fortinet/fortideceptor4.1.04.1.1+11

🔴Vulnerability Details

2
GHSA
GHSA-8qj2-9q5v-gh42: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiDeceptor 32025-01-15
CVEList
CVE-2024-35280: A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 52025-01-15

📋Vendor Advisories

1
Fortinet
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDe...2025-01-15
CVE-2024-35280 — Cross-site Scripting in Fortinet | cvebase