Description
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 through 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 management interface may allow a remote authenticated attacker to perform a stored cross site scripting (XSS) attack via sending request with specially crafted columnindex parameter.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiPortal version 6.0.12 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-44543 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 through 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 management interface may allow a remote authenticated attacker to perform a stored cross site scripting (XSS) attack via sending request with specially crafted columnindex parameter. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-313 |
|
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 23 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-23T14:51:08.943Z
Reserved: 2022-09-23T15:07:35.783Z
Link: CVE-2022-41336
Updated: 2024-08-03T12:42:46.229Z
Status : Modified
Published: 2023-01-03T17:15:10.463
Modified: 2024-11-21T07:23:04.760
Link: CVE-2022-41336
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD