Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-42752: Fortiguard

A improper neutralization of input during web page generation (‘cross-site scripting’) in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim’s host via crafted HTTP requests

CVE
#xss#vulnerability#web#java

PSIRT Advisories

FortiWLM - reflected cross-site scripting vulnerability in cgi_bin handlers

Summary

An improper neutralization of input during web page generation (‘Cross-site Scripting’) vulnerability [CWE-79] in FortiWLM may allow an
authenticated user to perform an XSS attack via crafted HTTP GET requests.

Affected Products

FortiWLM version 8.6.1 and below

Solutions

Upgrade to FortiWLM version 8.6.2 or above.

Acknowledgement

Internally discovered and reported by Mattia Fecit of Fortinet Product Security team.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907