CVE-2022-43955: XSS
An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote attacker to perform a reflected cross site scripting attack (XSS) via injecting malicious payload in log entries used to build report.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-43955?
CVE-2022-43955 is a vulnerability in the FortiWeb web interface that allows an unauthenticated remote attacker to perform a reflected cross-site scripting attack.
What is the severity of CVE-2022-43955?
The severity of CVE-2022-43955 is high with a CVSS score of 6.1.
Which versions of FortiWeb are affected by CVE-2022-43955?
FortiWeb versions 6.0.0 to 6.2.7, 6.3.0 to 6.3.21, 6.4.0 to 6.4.2, and 7.0.0 to 7.0.3 are affected by CVE-2022-43955.
How can an attacker exploit CVE-2022-43955?
An attacker can exploit CVE-2022-43955 by tricking a user into clicking on a specially crafted link that contains malicious code, which is then executed in the victim's browser.
Is there a fix available for CVE-2022-43955?
Yes, Fortinet has released patches to fix the vulnerability. It is recommended to update to the latest version of FortiWeb to mitigate the risk.