CVE-2022-41330

An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
fortinetCNA
8.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
fortinetfortiproxy
7.0.0 ≤
𝑥
< 7.0.8
fortinetfortiproxy
7.2.0 ≤
𝑥
< 7.2.2
fortinetfortios
6.2.0 ≤
𝑥
< 6.2.13
fortinetfortios
6.4.0 ≤
𝑥
< 6.4.12
fortinetfortios
7.0.0 ≤
𝑥
< 7.0.10
fortinetfortios
7.2.0 ≤
𝑥
< 7.2.4
𝑥
= Vulnerable software versions