Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-40965 | Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR. |
Fixes
Solution
Please upgrade to FortiSOAR version 7.2.1 or above
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-220 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:51:29.381Z
Reserved: 2022-08-16T14:17:48.481Z
Link: CVE-2022-38379
Updated: 2024-08-03T10:54:03.724Z
Status : Modified
Published: 2022-12-06T17:15:10.933
Modified: 2024-11-21T07:16:21.520
Link: CVE-2022-38379
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD