Medium severity4.3NVD Advisory· Published Nov 12, 2024· Updated Jun 17, 2026
CVE-2024-33510
CVE-2024-33510
Description
An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=7.0.0,<7.0.17
- (no CPE)range: <=7.4.3, <=7.2.9, <=7.0.16
- (no CPE)range: 7.4.0
Patches
Vulnerability mechanics
References
1- fortiguard.fortinet.com/psirt/FG-IR-24-033nvdVendor Advisory
News mentions
0No linked articles in our index yet.