PT-2022-5799 · Fortinet · Fortideceptor

Published

2022-08-16

·

Updated

2022-11-03

·

CVE-2022-38373

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiDeceptor versions 4.0.2, 4.1.0 through 4.1.1, 4.2.0
Description The issue is related to an improper neutralization of input during web page generation, which may allow an authenticated user to perform a cross-site scripting (XSS) attack. This can be achieved by sending requests with specially crafted lure resource ID. The vulnerability can be exploited by a remote attacker to conduct spoofing attacks.
Recommendations For FortiDeceptor version 4.0.2, update to a version that includes the fix for this issue. For FortiDeceptor versions 4.1.0 through 4.1.1, update to a version that includes the fix for this issue. For FortiDeceptor version 4.2.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the management interface to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-07200
CVE-2022-38373

Affected Products

Fortideceptor