CVE-2022-30304
published 2023-02-16CVE-2022-30304: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.67%
47.6th percentile
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parameter observed in the FortiWeb attack event logview in FortiAnalyzer.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | 6.0.0 – 6.0.11 | — |
| fortinet | fortianalyzer | 6.2.0 – 6.2.9 | — |
| fortinet | fortianalyzer | >= 6.4.0 < 6.4.9 | 6.4.9 |
| fortinet | fortianalyzer | 6.4.0 – 6.4.8 | — |
| fortinet | fortianalyzer | >= 7.0.0 < 7.0.5 | 7.0.5 |
| fortinet | fortianalyzer | 7.0.0 – 7.0.4 | — |
| fortinet | fortianalyzer | 7.2.0 – 7.2.1 | — |
| fortinet | fortiweb | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
XSS vulnerability due to AngularJS Client-Side Template injection
vendor_fortinet·2023-02-16·CVSS 4.3
CVE-2022-30304 [MEDIUM] CWE-79 XSS vulnerability due to AngularJS Client-Side Template injection
FG-IR-22-166: XSS vulnerability due to AngularJS Client-Side Template injection
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parameter observed in the FortiWeb attack event logview in FortiAnalyzer.
CVEs: CVE-2022-30304
CWEs: CWE-79
CVSS: 4.3 (medium)
Affected products: FortiAnalyzer, FortiWeb
GHSA
GHSA-xgcg-f8g4-r3mp: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7
ghsa_unreviewed·2023-02-16
CVE-2022-30304 [MEDIUM] CWE-79 GHSA-xgcg-f8g4-r3mp: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parameter observed in the FortiWeb attack event logview in FortiAnalyzer.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-16
Published