> Header injection in Web Filter warning page
[DATE: 14/07/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
3.4
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.
Revised on 2026-07-14 00:00:00