An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context.
This happens when the FortiGate has web filtering and category override enabled/configured.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://fortiguard.com/advisory/FG-IR-19-301 |     | 
History
                    Wed, 23 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | 
Fri, 21 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 21 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context. This happens when the FortiGate has web filtering and category override enabled/configured. | |
| First Time appeared | Fortinet Fortinet fortios | |
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:o:fortinet:fortios:6.2.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.2.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.2.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.2.3:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.2.4:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.2.5:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.2.6:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.2.7:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.2.8:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.2.9:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.4.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:6.4.1:*:*:*:*:*:*:* | |
| Vendors & Products | Fortinet Fortinet fortios | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: fortinet
Published: 2025-03-21T16:02:01.913Z
Updated: 2025-03-21T16:22:17.554Z
Reserved: 2019-09-09T00:00:00.000Z
Link: CVE-2019-16151
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-03-21T16:22:09.808Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-03-21T16:15:13.210
Modified: 2025-07-23T15:48:43.560
Link: CVE-2019-16151
 Redhat
                        Redhat
                    No data.