← Back to CVE List

CVE-2019-16151

Published: 2025-03-21T16:15Z
Last Modified: 2025-03-21T16:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context. This happens when the FortiGate has web filtering and category override enabled/configured. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt