Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3w7f-3j97-hfv4

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests

EPSS

Процентиль: 61%
0.00406
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
nvd
около 4 лет назад

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests

EPSS

Процентиль: 61%
0.00406
Низкий

Дефекты

CWE-79