CVE-2024-52967
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injectio
Severity
Low 3.3
CVSS 3.1
Exploited
Not listed
EPSS
0.004
29.7th percentile
Discovered by
Third party
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet
Description
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection.
Weakness: CWE-80
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiPortal | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiPortal
Credit
Fortinet is pleased to thank One NZ (Vodafone New Zealand) for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiPortal version 6.0.15 or above