Description
An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiOS version 7.2.4 or above Please upgrade to FortiOS version 7.0.8 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-44541 | An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-224 |
|
History
Wed, 23 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-23T14:46:36.145Z
Reserved: 2022-09-23T15:07:35.782Z
Link: CVE-2022-41334
Updated: 2024-08-03T12:42:46.200Z
Status : Modified
Published: 2023-02-16T19:15:13.443
Modified: 2024-11-21T07:23:04.483
Link: CVE-2022-41334
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD