CVE-2022-22304: XSS
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22304?
CVE-2022-22304 has a high severity rating due to its potential to allow unauthenticated attackers to perform XSS attacks.
How do I fix CVE-2022-22304?
To fix CVE-2022-22304, update FortiAuthenticator OWA Agent to version 2.3 or later which addresses the vulnerability.
Who is affected by CVE-2022-22304?
CVE-2022-22304 affects users running FortiAuthenticator OWA Agent for Microsoft Outlook Web Access versions 2.1 and 2.2.
What type of attack can be executed due to CVE-2022-22304?
CVE-2022-22304 allows an unauthenticated attacker to execute a cross-site scripting (XSS) attack using crafted HTTP GET requests.
What is the primary cause of CVE-2022-22304?
CVE-2022-22304 is caused by improper neutralization of input during web page generation in the FortiAuthenticator OWA Agent.