PT-2023-2440 · Fortinet · Fortiadc

CVE-2022-43952

·

Publicado

2023-04-11

·

Atualizado

2023-04-18

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions FortiADC versions 7.1.1 and below FortiADC versions 7.0.3 and below FortiADC versions 6.2.5 and below
Description The issue exists due to improper neutralization of input during web page generation, allowing a remote attacker to conduct a cross-site scripting (XSS) attack using specially crafted HTTP requests. This can enable an authenticated attacker to perform a cross-site scripting attack.
Recommendations For FortiADC versions 7.1.1 and below, update to a version above 7.1.1 to resolve the issue. For FortiADC versions 7.0.3 and below, update to a version above 7.0.3 to resolve the issue. For FortiADC versions 6.2.5 and below, update to a version above 6.2.5 to resolve the issue. As a temporary workaround, consider restricting access to crafted HTTP requests to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02225
CVE-2022-43952

Produtos afetados

Fortiadc