CVE-2022-39950
published 2022-11-02CVE-2022-39950: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.68%
48.2th percentile
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | 6.0.0 – 6.2.9 | — |
| fortinet | fortianalyzer | 6.4.0 – 6.4.8 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.4 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | 6.0.0 – 6.2.9 | — |
| fortinet | fortimanager | 6.4.0 – 6.4.8 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vghm-mjgx-gf75: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6
ghsa_unreviewed·2022-11-02·CVSS 6.1
CVE-2022-39950 [MEDIUM] CWE-79 GHSA-vghm-mjgx-gf75: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.
Fortinet
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAn...
vendor_fortinet·2022-11-02·CVSS 8.0
CVE-2022-39950 [MEDIUM] CWE-79 An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAn...
FG-IR-21-228: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAn...
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.
CVEs: CVE-2022-39950
CWEs: CWE-79
CVSS: 8.0 (high)
Affected products: FortiAnalyzer, FortiManager
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-02
Published