#VU80836 Protection Mechanism Failure in FortiWeb - CVE-2023-34984
Published: September 16, 2023
Vulnerability identifier: #VU80836
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
CVE-ID: CVE-2023-34984
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
FortiWeb
FortiWeb
Software vendor:
Fortinet, Inc
Fortinet, Inc
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures. An attacker can bypass implemented security restrictions against XSS and CSRF attacks.
Remediation
Install updates from vendor's website.