First published: Thu Feb 16 2023(Updated: )
An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=7.0.0<=7.0.7 | |
Fortinet FortiOS | >=7.2.0<=7.2.3 |
Please upgrade to FortiOS version 7.2.4 or above Please upgrade to FortiOS version 7.0.8 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-41334 is high.
CVE-2022-41334 is an improper neutralization of input during web page generation (CWE-79) vulnerability.
FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 are affected by CVE-2022-41334.
A remote, unauthenticated attacker can exploit CVE-2022-41334 by launching a cross-site scripting (XSS) attack via the "redir" parameter of the URL associated with "Sign in with Fort..." feature.
Yes, Fortinet has released fixes to address the vulnerability. It is recommended to update to the latest version of FortiOS.