cbcvebase.
CVE-2022-29057
published 2022-07-19

CVE-2022-29057: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and…

PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.49%
38.9th percentile
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload into the Management Console via various endpoints.

Affected

7 ranges
VendorProductVersion rangeFixed in
fortinetfortiedr
fortinetfortiedr
fortinetfortiedr
fortinetfortiedr
fortinetfortiedr>= 5.0.0 < 5.0.35.0.3
fortinetfortinet
fortinetfortinet_fortiedr
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.