First published: Wed Nov 02 2022(Updated: )
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted IP Address.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiADC | =7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-35851.
The severity of CVE-2022-35851 is high, with a severity value of 5.4.
The affected software of CVE-2022-35851 is FortiADC management interface version 7.1.0.
The CWE ID of this vulnerability is CWE-79.
Update the FortiADC management interface to a version that is not affected by this vulnerability.