QID 43934
Date Published: 2022-10-31
QID 43934: FortiOS - Cross-Site Scripting (XSS) Vulnerability in External Connectors of Security Fabric (FG-IR-21-222)
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors.
Affected Products
FortiOS version 7.2.0
FortiOS 6.4.0 through 6.4.9
FortiOS 7.0.0 through 7.0.5
Vulnerable version may allow an unauthenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-222
Vendor References
- FG-IR-21-222 -
www.fortiguard.com/psirt/FG-IR-21-222
CVEs related to QID 43934
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-222 |
|