First published: Tue Sep 06 2022(Updated: )
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiMail | <7.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-26114.
The severity of CVE-2022-26114 is medium with a CVSS score of 6.1.
The CWE ID of this vulnerability is CWE-79.
FortiMail version up to and excluding 7.2.0 is affected by this vulnerability.
An unauthenticated attacker can exploit CVE-2022-26114 by sending specially crafted mail messages to trigger a cross-site scripting (XSS) attack in the Webmail of FortiMail.