cbcvebase.
CVE-2022-38373
published 2022-11-02

CVE-2022-38373: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2…

PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.45%
36.0th percentile
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially crafted lure resource ID.

Affected

6 ranges
VendorProductVersion rangeFixed in
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor
fortinetfortinet_fortideceptor
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.