CVE-2022-41334Cross-site Scripting in Fortinet Fortios

Severity
6.1MEDIUMNVD
CNA8.8
EPSS
0.8%
top 26.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 16
Latest updateMar 14

Description

An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5fortinet/fortios7.2.07.2.3+1
NVDfortinet/fortios7.0.07.0.7+1

Patches

🔴Vulnerability Details

2
CVEList
CVE-2022-41334: An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 72023-02-16
GHSA
GHSA-9jfc-cmc5-x599: An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 72023-02-16

📋Vendor Advisories

2
CISA ICS
Siemens RUGGEDCOM APE1808 with Fortigate NGFW Devices2024-03-14
Fortinet
XSS vulnerability in the Login page when FortiCloud Sign-in is used2023-02-16
CVE-2022-41334 — Cross-site Scripting in Fortinet | cvebase