CVE-2022-35851: XSS
Published Nov 2, 2022
·Updated
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted IP Address.
Affected Software
1 affected component
Fortinet FortiADC=7.1.0
Event History
Nov 2, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-35851.
2
What is the severity of CVE-2022-35851?
The severity of CVE-2022-35851 is high, with a severity value of 5.4.
3
What is the affected software of CVE-2022-35851?
The affected software of CVE-2022-35851 is FortiADC management interface version 7.1.0.
4
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-79.
5
How can I fix CVE-2022-35851?
Update the FortiADC management interface to a version that is not affected by this vulnerability.