{"id":3549,"date":"2023-09-18T14:52:37","date_gmt":"2023-09-18T19:52:37","guid":{"rendered":"https:\/\/cert.pa\/?p=3549"},"modified":"2023-09-18T14:52:39","modified_gmt":"2023-09-18T19:52:39","slug":"csirt-panama-aviso-2023-09-18-fortios-y-fortiproxy-xss-almacenado-en-la-pagina-de-administracion-de-invitados","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=3549","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2023-09-18 FortiOS y FortiProxy: XSS almacenado en la p\u00e1gina de administraci\u00f3n de invitados"},"content":{"rendered":"\n<p>Fecha de publicaci\u00f3n<br>Gravedad: Alta<br>Fecha de publicaci\u00f3n: Sep. 14, 2023<br>https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-106<\/p>\n\n\n\n<p><br><strong>Sistemas Afectados:<\/strong><br>\u2022 FortiProxy, versi\u00f3n 7.2.0 hasta 7.2.4;<br>\u2022 FortiProxy, versi\u00f3n 7.0.0 hasta 7.0.10;<br>\u2022 FortiOS, versi\u00f3n 7.2.0 hasta 7.2.4;<br>\u2022 FortiOS, versi\u00f3n 7.0.0 hasta 7.0.11;<br>\u2022 FortiOS, versi\u00f3n 6.4.0 hasta 6.4.12;<br>\u2022 FortiOS, versi\u00f3n 6.2.0 hasta el 6.2.14;<\/p>\n\n\n\n<p><strong>I. Descripci\u00f3n<\/strong><br>El equipo CSE de Fortinet, ha notificado una vulnerabilidad de severidad alta que podr\u00eda permitir que un atacante autenticado, desencadene la ejecuci\u00f3n de c\u00f3digo JavaScript malicioso en una p\u00e1gina de gesti\u00f3n de invitados. <\/p>\n\n\n\n<p><br><strong>II. Referencia a soluciones, herramientas e informaci\u00f3n<\/strong><\/p>\n\n\n\n<p><strong>Soluci\u00f3n<\/strong>:<\/p>\n\n\n\n<p><strong>Actualizar a las versiones:<\/strong><br>\u2022 FortiProxy, versi\u00f3n 7.2.5 o superior.<br>\u2022 FortiProxy, versi\u00f3n 7.0.11 o superior.<br>\u2022 FortiOS, versi\u00f3n 7.4.0 o superior.<br>\u2022 FortiOS, versi\u00f3n 7.2.5 o superior.<br>\u2022 FortiOS, versi\u00f3n 7.0.12 o superior.<br>\u2022 FortiOS, versi\u00f3n 6.4.13 o superior.<br>\u2022 FortiOS, versi\u00f3n 6.2.15 o superior.<\/p>\n\n\n\n<p><strong>IV. Informaci\u00f3n de contacto<\/strong><br>CSIRT PANAMA<br>Computer Security Incident Response Team Autoridad Nacional para la Innovacion<br>Gubernamental<br>E-Mail: info@cert.pa<br>Phone: +507 520-CERT (2378)<br>Web: https:\/\/cert.pa<br>Twitter: @CSIRTPanama<br>Facebook: http:\/\/www.facebook.com\/CSIRTPanama<br>Key ID: 16F2B124<\/p>\n\n\n<p>\u00a0<\/p>\n<p class=\"centrable-test-content\" style=\"line-height: 18.75pt; background: white; margin: 0cm 0cm 6.0pt 0cm;\">\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p>Fecha de publicaci\u00f3nGravedad: AltaFecha de publicaci\u00f3n: Sep. 14, 2023https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-106 Sistemas Afectados:\u2022 FortiProxy, versi\u00f3n 7.2.0 hasta 7.2.4;\u2022 FortiProxy, versi\u00f3n 7.0.0 hasta 7.0.10;\u2022 FortiOS, versi\u00f3n 7.2.0 hasta 7.2.4;\u2022 FortiOS, versi\u00f3n 7.0.0 hasta 7.0.11;\u2022 FortiOS, versi\u00f3n 6.4.0 hasta&#8230;<\/p>\n","protected":false},"author":4,"featured_media":3241,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-3549","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/3549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3549"}],"version-history":[{"count":2,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/3549\/revisions"}],"predecessor-version":[{"id":3552,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/3549\/revisions\/3552"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/3241"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3549"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3549"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}