CVE-2022-30304

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parameter observed in the FortiWeb attack event logview in FortiAnalyzer.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
fortinetCNA
4.2 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:F/RL:X/RC:X
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
fortinetfortianalyzer
6.0.0 ≤
𝑥
≤ 6.0.11
fortinetfortianalyzer
6.2.0 ≤
𝑥
≤ 6.2.9
fortinetfortianalyzer
6.4.0 ≤
𝑥
< 6.4.9
fortinetfortianalyzer
7.0.0 ≤
𝑥
< 7.0.5
fortinetfortianalyzer
7.2.0
fortinetfortianalyzer
7.2.1
𝑥
= Vulnerable software versions