CVE-2022-23438
18.07.2022, 18:15
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
Vendor | Product | Version |
---|---|---|
fortinet | fortios | 𝑥 ≤ 6.4.9 |
fortinet | fortios | 7.0.0 ≤ 𝑥 ≤ 7.0.5 |
𝑥
= Vulnerable software versions