CVE-2022-38373: XSS
Published Nov 2, 2022
·Updated
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially crafted lure resource ID.
Affected Software
4 affected components
Fortinet FortiDeceptor=4.0.2
Fortinet FortiDeceptor=4.1.0
Fortinet FortiDeceptor=4.1.1
Fortinet FortiDeceptor=4.2.0
Event History
Nov 2, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-38373.
2
What is the severity of CVE-2022-38373?
The severity of CVE-2022-38373 is high.
3
What is the affected software?
The affected software is FortiDeceptor version 4.0.2, 4.1.0 through 4.1.1, and 4.2.0.
4
What is the CWE of CVE-2022-38373?
The CWE of CVE-2022-38373 is CWE-79.
5
How can an authenticated user exploit CVE-2022-38373?
An authenticated user can exploit CVE-2022-38373 by sending requests with specially crafted lure resource ID, which can lead to a cross-site scripting (XSS) attack.