CVE-2022-29057
19.07.2022, 14:15
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload into the Management Console via various endpoints.
Vendor | Product | Version |
---|---|---|
fortinet | fortiedr | 5.0.0 ≤ 𝑥 < 5.0.3 |
fortinet | fortiedr | 4.0.0 |
fortinet | fortiedr | 5.0.3 |
fortinet | fortiedr | 5.0.3:patch1 |
fortinet | fortiedr | 5.0.3:patch2 |
fortinet | fortiedr | 5.0.3:patch3 |
fortinet | fortiedr | 5.0.3:patch4 |
fortinet | fortiedr | 5.0.3:patch5 |
fortinet | fortiedr | 5.0.3:patch6 |
fortinet | fortiedr | 5.1.0 |
𝑥
= Vulnerable software versions