CVE-2022-38373
Severity
5.4MEDIUM
EPSS
0.8%
top 25.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 2
Description
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially crafted lure resource ID.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9
Affected Packages2 packages
š“Vulnerability Details
2GHSAā¶
GHSA-2mx3-6c3v-gprg: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4ā2022-11-02
CVEListā¶
CVE-2022-38373: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4ā2022-11-02
šVendor Advisories
1Fortinetā¶
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interf...ā2022-11-02