Description
An URL Redirection to Untrusted Site vulnerabilities [CWE-601] in FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions; FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests.
Problem types
Product status
7.6.0
7.4.0
7.2.0
7.0.0
6.4.0
7.6.0
7.4.0
7.2.0
7.0.0
References
fortiguard.fortinet.com/psirt/FG-IR-24-542