CVE-2022-26114
Severity
6.1MEDIUM
EPSS
0.8%
top 25.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 6
Latest updateSep 7
Description
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7
Affected Packages2 packages
š“Vulnerability Details
2GHSAā¶
GHSA-fj88-8w22-m925: An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7ā2022-09-07
CVEListā¶
CVE-2022-26114: An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7ā2022-09-06
šVendor Advisories
1Fortinetā¶
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before...ā2022-09-06