First published: Mon Jul 18 2022(Updated: )
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet Fortiauthenticator Agent For Microsoft Outlook Web Access | =2.1 | |
Fortinet Fortiauthenticator Agent For Microsoft Outlook Web Access | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22304 has a high severity rating due to its potential to allow unauthenticated attackers to perform XSS attacks.
To fix CVE-2022-22304, update FortiAuthenticator OWA Agent to version 2.3 or later which addresses the vulnerability.
CVE-2022-22304 affects users running FortiAuthenticator OWA Agent for Microsoft Outlook Web Access versions 2.1 and 2.2.
CVE-2022-22304 allows an unauthenticated attacker to execute a cross-site scripting (XSS) attack using crafted HTTP GET requests.
CVE-2022-22304 is caused by improper neutralization of input during web page generation in the FortiAuthenticator OWA Agent.