CVE-2024-35280 — Cross-site Scripting in Fortinet Fortideceptor
Severity
6.1MEDIUMNVD
CNA5.4
EPSS
0.7%
top 28.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 15
Description
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions, FortiDeceptor 4.0 all versions, FortiDeceptor 3.3 all versions, FortiDeceptor 3.2 all versions, FortiDeceptor 3.1 all versions, FortiDeceptor 3.0 all versions may allow an attacker to p…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-8qj2-9q5v-gh42: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiDeceptor 3↗2025-01-15
CVEList▶
CVE-2024-35280: A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5↗2025-01-15
📋Vendor Advisories
1Fortinet▶
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDe...↗2025-01-15