PT-2022-6551 · Fortinet · Fortiauthenticator

Published

2022-07-13

·

Updated

2023-04-18

·

CVE-2022-35850

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FortiAuthenticator versions 6.1 through 6.4.4
Description The issue is related to the improper neutralization of script-related HTML tags in a web page, which may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password" page. This can be exploited by an attacker to perform actions such as stealing user sessions or sensitive data.
Recommendations For FortiAuthenticator versions 6.1 through 6.4.4, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the "reset-password" page until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-02342
CVE-2022-35850

Affected Products

Fortiauthenticator