CVE-2024-52967

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injectio

Severity
Low 3.3
CVSS 3.1
Exploited
Not listed
EPSS
0.004
27.8th percentile
Discovered by
Not disclosed
Published
Jan 14, 2025
Assigned by fortinet

Description

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection.

Weakness: CWE-80

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiPortal

Vendor remediation

Please upgrade to FortiPortal version 6.0.15 or above