Other security products
CVE-2024-35280: Cross-site scripting in FortiDeceptor
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions, FortiDeceptor 4.0 all versions, FortiDeceptor 3.3 all versions, FortiDeceptor 3.2 all versions, FortiDeceptor 3.1 all versions, FortiDeceptor 3.0 all versions may allow an attacker to perform a reflected cross-site scripting attack in the recovery endpoints
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiDeceptor 5.3 | 5.3.1 or later |
| FortiDeceptor 5.2 | 5.2.1 or later |
| FortiDeceptor 5.1 | See the advisory |
| FortiDeceptor 5.0 | See the advisory |
| FortiDeceptor 4.3 | See the advisory |
| FortiDeceptor 4.2 | See the advisory |
| FortiDeceptor 4.1.0 to 4.1.1 | Upgrade past 4.1.1; see the advisory |
| FortiDeceptor 4.0.0 to 4.0.2 | Upgrade past 4.0.2; see the advisory |
| FortiDeceptor 3.3.0 to 3.3.3 | Upgrade past 3.3.3; see the advisory |
| FortiDeceptor 3.2.0 to 3.2.2 | Upgrade past 3.2.2; see the advisory |
| FortiDeceptor 3.1.0 to 3.1.1 | Upgrade past 3.1.1; see the advisory |
| FortiDeceptor 3.0.0 to 3.0.2 | Upgrade past 3.0.2; see the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions, FortiDeceptor 4.0 all versions, FortiDeceptor 3.3 all versions, FortiDeceptor 3.2 all versions, FortiDeceptor 3.1 all versions, FortiDeceptor 3.0 all versions may allow an attacker to perform a reflected cross-site scripting attack in the recovery endpoints
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.