CVE-2022-23438
published 2022-07-18CVE-2022-23438: An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.64%
46.6th percentile
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet_fortios | — | — |
| fortinet | fortios | <= 6.4.9 | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 7.0.0 – 7.0.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
XSS vulnerability observed in the authentication replacement pages
vendor_fortinet·2022-07-18·CVSS 4.7
CVE-2022-23438 [MEDIUM] CWE-79 XSS vulnerability observed in the authentication replacement pages
FG-IR-21-057: XSS vulnerability observed in the authentication replacement pages
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
CVEs: CVE-2022-23438
CWEs: CWE-79
CVSS: 4.7 (medium)
Affected products: FortiOS
GHSA
GHSA-j64m-j3jq-cvj5: An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7
ghsa_unreviewed·2022-07-19
CVE-2022-23438 [MEDIUM] CWE-79 GHSA-j64m-j3jq-cvj5: An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-18
Published