A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via storing malicious payloads in replacement messages.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-43951 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via storing malicious payloads in replacement messages. |
Fixes
Solution
Please upgrade to FortiOS version 7.2.2 Please upgrade to FortiOS version 7.0.7 Please upgrade to FortiOS version 6.4.10 or above
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://fortiguard.com/psirt/FG-IR-21-248 |
![]() ![]() |
History
Wed, 23 Oct 2024 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:51:47.554Z
Reserved: 2022-09-14T13:17:43.617Z
Link: CVE-2022-40680

Updated: 2024-08-03T12:21:46.588Z

Status : Modified
Published: 2022-12-06T17:15:10.997
Modified: 2024-11-21T07:21:50.600
Link: CVE-2022-40680

No data.

No data.