CVE-2024-33510

CVSS V2 None CVSS V3 None
Description
An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.
Overview
  • CVE ID
  • CVE-2024-33510
  • Assigner
  • fortinet
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-12T18:53:45.839Z
  • Last Modified Date
  • 2024-11-12T18:53:45.839Z
References
History
Created Old Value New Value Data Type Notes
2024-11-13 13:25:20 Added to TrackCVE