CVE-2022-41336: XSS
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 through 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 management interface may allow a remote authenticated attacker to perform a stored cross site scripting (XSS) attack via sending request with specially crafted columnindex parameter.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this FortiPortal vulnerability?
The vulnerability ID for this FortiPortal vulnerability is CVE-2022-41336.
What is the severity of CVE-2022-41336?
The severity of CVE-2022-41336 is medium with a CVSS score of 4.8.
Which versions of FortiPortal are affected by CVE-2022-41336?
FortiPortal versions 6.0.0 through 6.0.11 and all versions of 5.3, 5.2, 5.1, and 5.0 management interface are affected by CVE-2022-41336.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
How can a remote attacker exploit CVE-2022-41336?
A remote authenticated attacker can exploit CVE-2022-41336 by sending malicious input through the management interface, which may allow for a stored cross-site scripting (XSS) attack.