An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-44541 An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked.
Fixes

Solution

Please upgrade to FortiOS version 7.2.4 or above Please upgrade to FortiOS version 7.0.8 or above


Workaround

No workaround given by the vendor.

References
History

Wed, 23 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2024-10-23T14:46:36.145Z

Reserved: 2022-09-23T15:07:35.782Z

Link: CVE-2022-41334

cve-icon Vulnrichment

Updated: 2024-08-03T12:42:46.200Z

cve-icon NVD

Status : Modified

Published: 2023-02-16T19:15:13.443

Modified: 2024-11-21T07:23:04.483

Link: CVE-2022-41334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.