Cross-site Scripting Vulnerability in FortiADC GUI by Fortinet
CVE-2023-37933
8.6HIGH
What is CVE-2023-37933?
A vulnerability in the FortiADC GUI allows authenticated attackers to exploit an improper neutralization of input when generating web pages, leading to the potential execution of malicious scripts. This Cross-site Scripting (XSS) vulnerability can be triggered via specially crafted HTTP or HTTPS requests, posing significant risks to the security of web applications. Users are advised to update to the latest versions and follow secure coding practices to mitigate this risk.
Affected Version(s)
FortiADC 7.4.0
FortiADC 7.2.0 <= 7.2.1
FortiADC 7.1.0 <= 7.1.3