Page 7 of 61 results (0.004 seconds)

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

17 Mar 2020 — An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Disclaimer Description of a Replacement Message. Una vulnerabilidad de neutralización inapropiada de entrada en FortiWeb, permite a un atacante autenticado remoto realizar un ataque de tipo cross-site scripting (XSS) almacenado por medio del Disclaimer Description de un Replacement Message. • https://fortiguard.com/advisory/FG-IR-20-001 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •