Medium severity4.1NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026
CVE-2023-22641
CVE-2023-22641
Description
A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows an authenticated attacker to execute unauthorized code or commands via specially crafted requests.
Affected products
6cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.0.0,<=2.0.12
- (no CPE)range: 7.2.0 - 7.2.2, 7.0.0 - 7.0.8, 2.0, 1.2, 1.1, 1.0
- (no CPE)range: 7.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-479nvdVendor Advisory
News mentions
0No linked articles in our index yet.