A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an attacker to execute unauthorized code or commands via the URL and User fields observed in the traffic and event logviews.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-232 |
|
History
Fri, 25 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-25T13:20:38.157Z
Reserved: 2022-08-16T00:00:00
Link: CVE-2022-38374
Updated: 2024-08-03T10:54:03.687Z
Status : Modified
Published: 2022-11-02T12:15:54.303
Modified: 2024-11-21T07:16:20.850
Link: CVE-2022-38374
No data.
OpenCVE Enrichment
No data.
Weaknesses