CVE-2022-26114

Severity
6.1MEDIUM
EPSS
0.8%
top 25.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 6
Latest updateSep 7

Description

An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

ā–¶NVDfortinet/fortimail< 7.2.0
ā–¶CVEListV5fortinet/fortinet_fortimailFortiMail before 7.2.0

šŸ”“Vulnerability Details

2
GHSA
GHSA-fj88-8w22-m925: An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7↗2022-09-07
ā–¶
CVEList
CVE-2022-26114: An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7↗2022-09-06
ā–¶

šŸ“‹Vendor Advisories

1
Fortinet
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before...↗2022-09-06
ā–¶
CVE-2022-26114 (MEDIUM CVSS 6.1) | An improper neutralization of input | cvebase.io