Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-442w-3vhj-m8rc

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler

EPSS

Процентиль: 67%
0.00545
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler

EPSS

Процентиль: 67%
0.00545
Низкий

Дефекты

CWE-79