CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It affects FortiOS. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
Original NVD Description
AnĀ improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.
Related CVEs
Other vulnerabilities affecting the same vendor(s)