CVE-2022-38373

Severity
5.4MEDIUM
EPSS
0.8%
top 25.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2

Description

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially crafted lure resource ID.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages2 packages

ā–¶NVDfortinet/fortideceptor4 versions+3
ā–¶CVEListV5fortinet/fortinet_fortideceptorFortiDeceptor 4.2.0, 4.1.0 through 4.1.1, 4.0.2

šŸ”“Vulnerability Details

2
GHSA
GHSA-2mx3-6c3v-gprg: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4↗2022-11-02
ā–¶
CVEList
CVE-2022-38373: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4↗2022-11-02
ā–¶

šŸ“‹Vendor Advisories

1
Fortinet
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interf...↗2022-11-02
ā–¶
CVE-2022-38373 (MEDIUM CVSS 5.4) | An improper neutralization of input | cvebase.io