CVE-2024-35280
published 2025-01-15CVE-2024-35280: A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.28%
19.7th percentile
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions, FortiDeceptor 4.0 all versions, FortiDeceptor 3.3 all versions, FortiDeceptor 3.2 all versions, FortiDeceptor 3.1 all versions, FortiDeceptor 3.0 all versions may allow an attacker to perform a reflected cross-site scripting attack in the recovery endpoints
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | >= 3.0.0 < 5.2.1 | 5.2.1 |
| fortinet | fortideceptor | 3.0.0 – 3.0.2 | — |
| fortinet | fortideceptor | 3.1.0 – 3.1.1 | — |
| fortinet | fortideceptor | 3.2.0 – 3.2.2 | — |
| fortinet | fortideceptor | 3.3.0 – 3.3.3 | — |
| fortinet | fortideceptor | 4.0.0 – 4.0.2 | — |
| fortinet | fortideceptor | 4.1.0 – 4.1.1 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8qj2-9q5v-gh42: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiDeceptor 3
ghsa_unreviewed·2025-01-15
CVE-2024-35280 [MEDIUM] CWE-79 GHSA-8qj2-9q5v-gh42: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiDeceptor 3
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiDeceptor 3.x all versions, 4.x all versions, 5.0 all versions, 5.1 all versions, version 5.2.0, and version 5.3.0 may allow an attacker to perform a reflected cross-site scripting attack in the recovery endpoints
Fortinet
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDe...
vendor_fortinet·2025-01-15·CVSS 5.4
CVE-2024-35280 [MEDIUM] CWE-79 A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDe...
FG-IR-24-010: A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDe...
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions, FortiDeceptor 4.0 all versions, FortiDeceptor 3.3 all versions, FortiDeceptor 3.2 all versions, FortiDeceptor 3.1 all versions, FortiDeceptor 3.0 all versions may allow an attacker to perform a reflected cross-site scripting attack in the recovery endpoints
CVEs: CVE-2024-35280
CWEs: CWE-79
CVSS: 5.4 (medium)
Affected products: FortiDeceptor,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-15
Published