CVE-2019-16151 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthentic…
Medium CVSS: 4.7

CVE-2019-16151

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context.
This happens when the FortiGate has web filtering and category override enabled/configured.
Vendor
Fortinet
Product
Fortios
CWE
CWE-79
Yayın Tarihi
2025-03-21 16:15:13
Güncelleme
2025-07-23 15:48:43
Source Identifier
psirt@fortinet.com
KEV Date Added
-

Kategoriler

Referanslar