Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xx4-8wj3-477v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.

EPSS

Процентиль: 98%
0.57842
Средний

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 5 лет назад

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.

CVSS3: 6.1
fstec
около 5 лет назад

Уязвимость графического интерфейса межсетевого экрана веб-приложений FortiWeb, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 98%
0.57842
Средний

Дефекты

CWE-79