> SSL-VPN Reflected XSS
[DATE: 14/07/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
6.1
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests.
Revised on 2026-07-14 00:00:00