Headline
CVE-2022-43952: Fortiguard
An improper neutralization of input during web page generation (‘Cross-site Scripting’) vulnerability [CWE-79] in FortiADC version 7.1.1 and below, version 7.0.3 and below, version 6.2.5 and below may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.
** PSIRT Advisories**
FortiADC - Cross-Site Scripting in Fabric Connectors
Summary
An improper neutralization of input during web page generation (‘Cross-site Scripting’) vulnerability [CWE-79] in FortiADC may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.
Affected Products
At least
FortiADC version 7.1.0 through 7.1.1
FortiADC version 7.0.0 through 7.0.3
FortiADC version 6.2.0 through 6.2.5
Solutions
Please upgrade to FortiADC version 7.1.2 or above
Please upgrade to FortiADC version 7.0.4 or above
Please upgrade to FortiADC version 6.2.6 or above
Timeline
2023-03-21: Initial publication