Headline
CVE-2022-23438: Fortiguard
An improper neutralization of input during web page generation (‘Cross-site Scripting’) [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
** PSIRT Advisories**
FortiOS – XSS vulnerability observed in the authentication replacement pages
Summary
An improper neutralization of input during web page generation (‘Cross-site Scripting’) [CWE-79] vulnerability in FortiOS may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
Affected Products
FortiOS version 7.0.0 through 7.0.5
FortiOS version 6.4.0 through 6.4.9
Solutions
Please upgrade to FortiGate version 7.0.6 or above.
Please upgrade to FortiGate version 7.2.0 or above.
Acknowledgement
Fortinet is pleased to thank Hebun İlhanlı from Intertech for reporting this vulnerability under responsible disclosure.
Related news
Four high, six medium, and one low severity issue fixed