Vulnerability Details CVE-2023-37933
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP or HTTPs requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.4%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-37933
-
cpe:2.3:a:fortinet:fortiadc:5.3.0
-
cpe:2.3:a:fortinet:fortiadc:5.3.1
-
cpe:2.3:a:fortinet:fortiadc:5.3.2
-
cpe:2.3:a:fortinet:fortiadc:5.3.3
-
cpe:2.3:a:fortinet:fortiadc:5.3.4
-
cpe:2.3:a:fortinet:fortiadc:5.3.5
-
cpe:2.3:a:fortinet:fortiadc:5.3.6
-
cpe:2.3:a:fortinet:fortiadc:5.3.7
-
cpe:2.3:a:fortinet:fortiadc:5.4.0
-
cpe:2.3:a:fortinet:fortiadc:5.4.1
-
cpe:2.3:a:fortinet:fortiadc:5.4.2
-
cpe:2.3:a:fortinet:fortiadc:5.4.3
-
cpe:2.3:a:fortinet:fortiadc:5.4.4
-
cpe:2.3:a:fortinet:fortiadc:5.4.5
-
cpe:2.3:a:fortinet:fortiadc:6.0.0
-
cpe:2.3:a:fortinet:fortiadc:6.0.1
-
cpe:2.3:a:fortinet:fortiadc:6.0.2
-
cpe:2.3:a:fortinet:fortiadc:6.0.3
-
cpe:2.3:a:fortinet:fortiadc:6.0.4
-
cpe:2.3:a:fortinet:fortiadc:6.1.0
-
cpe:2.3:a:fortinet:fortiadc:6.1.1
-
cpe:2.3:a:fortinet:fortiadc:6.1.2
-
cpe:2.3:a:fortinet:fortiadc:6.1.3
-
cpe:2.3:a:fortinet:fortiadc:6.1.4
-
cpe:2.3:a:fortinet:fortiadc:6.1.5
-
cpe:2.3:a:fortinet:fortiadc:6.1.6
-
cpe:2.3:a:fortinet:fortiadc:6.2.0
-
cpe:2.3:a:fortinet:fortiadc:6.2.1
-
cpe:2.3:a:fortinet:fortiadc:6.2.2
-
cpe:2.3:a:fortinet:fortiadc:6.2.3
-
cpe:2.3:a:fortinet:fortiadc:6.2.4
-
cpe:2.3:a:fortinet:fortiadc:6.2.5
-
cpe:2.3:a:fortinet:fortiadc:6.2.6
-
cpe:2.3:a:fortinet:fortiadc:7.0.0
-
cpe:2.3:a:fortinet:fortiadc:7.0.1
-
cpe:2.3:a:fortinet:fortiadc:7.0.2
-
cpe:2.3:a:fortinet:fortiadc:7.0.3
-
cpe:2.3:a:fortinet:fortiadc:7.0.4
-
cpe:2.3:a:fortinet:fortiadc:7.0.5
-
cpe:2.3:a:fortinet:fortiadc:7.1.0
-
cpe:2.3:a:fortinet:fortiadc:7.1.1
-
cpe:2.3:a:fortinet:fortiadc:7.1.2
-
cpe:2.3:a:fortinet:fortiadc:7.1.3
-
cpe:2.3:a:fortinet:fortiadc:7.2.0
-
cpe:2.3:a:fortinet:fortiadc:7.2.1
-
cpe:2.3:a:fortinet:fortiadc:7.4.0