Description
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload into the Management Console via various endpoints.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33470 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload into the Management Console via various endpoints. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-077 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:55:20.971Z
Reserved: 2022-04-11T00:00:00.000Z
Link: CVE-2022-29057
Updated: 2024-08-03T06:10:59.274Z
Status : Modified
Published: 2022-07-19T14:15:08.550
Modified: 2024-11-21T06:58:25.400
Link: CVE-2022-29057
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD