First published: Mon Jul 18 2022(Updated: )
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
FortiOS | <=6.4.9 | |
FortiOS | >=7.0.0<=7.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23438 is rated as a high severity vulnerability due to its potential for reflected cross-site scripting attacks.
To fix CVE-2022-23438, upgrade your FortiOS to version 6.4.10 or later or 7.0.6 or later.
CVE-2022-23438 can facilitate reflected cross-site scripting (XSS) attacks, allowing attackers to execute scripts in the context of the victim's browser.
CVE-2022-23438 affects FortiOS versions 6.4.9 and prior as well as 7.0.5 and prior.
No, CVE-2022-23438 can be exploited by unauthenticated remote attackers.