Text injection in FortiProxy and FortiOS - CVE-2024-33510
Published: November 18, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to improper input validation within the SSL-VPN web user interface. A remote attacker can trick the victim into clicking on a specially crafted link and display arbitrary text on the SSL-VPN web user page, leading to a potential spoofing attack.
Affected software
FortiOS
How to mitigate CVE-2024-33510
FortiOS - addressed in versions 7.2.9, 7.4.4