PT-2023-2440 · Fortinet · Fortiadc
CVE-2022-43952
·
Publicado
2023-04-11
·
Atualizado
2023-04-18
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FortiADC versions 7.1.1 and below
FortiADC versions 7.0.3 and below
FortiADC versions 6.2.5 and below
Description
The issue exists due to improper neutralization of input during web page generation, allowing a remote attacker to conduct a cross-site scripting (XSS) attack using specially crafted HTTP requests. This can enable an authenticated attacker to perform a cross-site scripting attack.
Recommendations
For FortiADC versions 7.1.1 and below, update to a version above 7.1.1 to resolve the issue.
For FortiADC versions 7.0.3 and below, update to a version above 7.0.3 to resolve the issue.
For FortiADC versions 6.2.5 and below, update to a version above 6.2.5 to resolve the issue.
As a temporary workaround, consider restricting access to crafted HTTP requests to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fortiadc