CVE-2022-22304
18.07.2022, 17:15
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Vendor | Product | Version |
---|---|---|
fortinet | fortiauthenticator_agent_for_microsoft_outlook_web_access | 2.1 |
fortinet | fortiauthenticator_agent_for_microsoft_outlook_web_access | 2.2 |
𝑥
= Vulnerable software versions