CVE-2024-35280

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions, FortiDeceptor 4.0 all versions, FortiDeceptor 3.3 all versions, FortiDeceptor 3.2 all versions, FortiDeceptor 3.1 all versions, FortiDeceptor 3.0 all versions may allow an attacker to perform a reflected cross-site scripting attack in the recovery endpoints
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortideceptor:5.3.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-15 11:15

Updated : 2026-02-04 14:16


NVD link : CVE-2024-35280

Mitre link : CVE-2024-35280

CVE.ORG link : CVE-2024-35280


JSON object : View

Products Affected

fortinet

  • fortideceptor
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')