Description
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28513 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-21-057 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:55:49.551Z
Reserved: 2022-01-19T00:00:00.000Z
Link: CVE-2022-23438
Updated: 2024-08-03T03:43:45.631Z
Status : Modified
Published: 2022-07-18T18:15:08.963
Modified: 2024-11-21T06:48:33.510
Link: CVE-2022-23438
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD