Security Advisory

CVE-2024-33510

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-11-12 18:53:45
Last updated 2024-11-13 18:45:40
Assigner fortinet
CVSS score 3.6
State PUBLISHED

Description

An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.