PT-2023-2440 · Fortinet · Fortiadc

Published

2023-04-11

·

Updated

2023-04-18

·

CVE-2022-43952

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions FortiADC versions 7.1.1 and below FortiADC versions 7.0.3 and below FortiADC versions 6.2.5 and below
Description The issue exists due to improper neutralization of input during web page generation, allowing a remote attacker to conduct a cross-site scripting (XSS) attack using specially crafted HTTP requests. This can enable an authenticated attacker to perform a cross-site scripting attack.
Recommendations For FortiADC versions 7.1.1 and below, update to a version above 7.1.1 to resolve the issue. For FortiADC versions 7.0.3 and below, update to a version above 7.0.3 to resolve the issue. For FortiADC versions 6.2.5 and below, update to a version above 6.2.5 to resolve the issue. As a temporary workaround, consider restricting access to crafted HTTP requests to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-02225
CVE-2022-43952

Affected Products

Fortiadc