CVE-2022-43955

An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote attacker to perform a reflected cross site scripting attack (XSS) via injecting malicious payload in log entries used to build report.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-428 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

18 Apr 2023, 18:55

Type Values Removed Values Added
CWE CWE-79
References (MISC) https://fortiguard.com/psirt/FG-IR-22-428 - (MISC) https://fortiguard.com/psirt/FG-IR-22-428 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
First Time Fortinet
Fortinet fortiweb

11 Apr 2023, 17:21

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-11 17:15

Updated : 2023-12-10 15:01


NVD link : CVE-2022-43955

Mitre link : CVE-2022-43955

CVE.ORG link : CVE-2022-43955


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')