Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-18299
HistoryFeb 20, 2023 - 12:00 a.m.

Fortinet FortiWeb Cross-Site Scripting Vulnerability (CNVD-2023-18299)

2023-02-2000:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
fortinet fortiweb
web application layer firewall
cross-site scripting
sql injection
cookie poisoning
schema poisoning
attack protection
fortianalyzer
fortiweb logs
vulnerability exploit
stored xss attacks
url parameters

EPSS

0.001

Percentile

49.8%

Fortinet FortiWeb is a Web application layer firewall from Fortinet that blocks threats such as cross-site scripting, SQL injection, cookie poisoning, schema poisoning and other attacks, secures Web applications and protects sensitive database content. A cross-site scripting vulnerability exists that can be exploited by attackers to execute stored cross-site scripting (XSS) attacks via URL parameters observed in FortiAnalyzer’s FortiWeb attack event log view.

EPSS

0.001

Percentile

49.8%

Related for CNVD-2023-18299