Cross Site Scripting vulnerabilities in administrative interface

Summary

Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiOS & FortiProxy administrative interface may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP or HTTPS GET requests.

Version Affected Solution
FortiOS 7.4 Not affected Not Applicable
FortiOS 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiOS 7.0 7.0.0 through 7.0.9 Upgrade to 7.0.11 or above
FortiOS 6.4 6.4.0 through 6.4.11 Upgrade to 6.4.12 or above
FortiOS 6.2 6.2.0 through 6.2.12 Upgrade to 6.2.13 or above
FortiProxy 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiProxy 7.0 7.0.0 through 7.0.7 Upgrade to 7.0.8 or above
FortiProxy 2.0 Not affected Not Applicable
FortiProxy 1.2 Not affected Not Applicable
FortiProxy 1.1 Not affected Not Applicable
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2023-04-11: Initial publication