> Open Redirect and XSS in Web Filter warning page
[DATE: 14/10/2025 07:00]
[LANGUAGE: EN]
An Improper Neutralization of Input During Web Page Generation and URL Redirection to Untrusted Site vulnerabilities [CWE-79, CWE-601] in FortiOS, FortiProxy and FortiSASE may allow an unauthenticated attacker to perform a reflected cross site scripting (XSS) or an open redirect attack via crafted HTTP requests. Revised on 2025-10-14 00:00:00