CVE-2022-38374: XSS
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an attacker to execute unauthorized code or commands via the URL and User fields observed in the traffic and event logviews.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38374?
The severity of CVE-2022-38374 is high.
How does CVE-2022-38374 occur?
CVE-2022-38374 occurs due to an improper neutralization of input during web page generation, leading to cross-site scripting (XSS) vulnerabilities.
What is the affected software of CVE-2022-38374?
The affected software of CVE-2022-38374 is Fortinet FortiADC versions 6.2.0 - 6.2.4 and 7.0.0 - 7.0.2.
How can an attacker exploit CVE-2022-38374?
An attacker can exploit CVE-2022-38374 by executing unauthorized code or commands through the URL and User fields observed in the traffic and event logviews.
Is there a fix available for CVE-2022-38374?
Yes, Fortinet has released a fix for CVE-2022-38374. Please refer to the vendor's advisory for more information.