CVE-2022-26114: XSS
Published Sep 6, 2022
·Updated
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.
Affected Software
1 affected component
Fortinet FortiMail<7.2.0
Event History
Sep 6, 2022
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-26114.
2
What is the severity of CVE-2022-26114?
The severity of CVE-2022-26114 is medium with a CVSS score of 6.1.
3
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-79.
4
Which version of FortiMail is affected by this vulnerability?
FortiMail version up to and excluding 7.2.0 is affected by this vulnerability.
5
How can an unauthenticated attacker exploit CVE-2022-26114?
An unauthenticated attacker can exploit CVE-2022-26114 by sending specially crafted mail messages to trigger a cross-site scripting (XSS) attack in the Webmail of FortiMail.