> Header injection in captive portal authentication form
[DATE: 14/07/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
3.1
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests.
Revised on 2026-07-14 00:00:00