FortiProxy & FortiOS - XSS vulnerability in Web Filter Block Override Form
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiProxy and FortiOS web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
FortiOS version 7.0.3 and below,
FortiOS version 6.4.8 and below,
FortiOS version 6.2.10 and below,
FortiOS version 6.0.14 to 6.0.0.
FortiProxy version 7.0.1 and below,
FortiProxy version 2.0.7 to 2.0.0.
SolutionsPlease upgrade to FortiOS version 7.0.4 or above
Please upgrade to FortiOS version 6.4.9 or above
Please upgrade to FortiOS version 6.2.11 or above
Please upgrade to FortiProxy version 7.0.2 or above
Please upgrade to FortiProxy version 2.0.8 or above