Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-22304: Fortiguard

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

CVE
#xss#vulnerability#web#microsoft#auth

** PSIRT Advisories**

FortiAuthenticator - XSS vulnerability in OWA login page

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

Affected Products

FortiAuthenticator Agent for Microsoft OWA version 2.2,
FortiAuthenticator Agent for Microsoft OWA version 2.1.

Solutions

Please upgrade to FortiAuthenticator Agent for Microsoft OWA version 2.3 or above.

Acknowledgement

Fortinet is pleased to thank Mohamad Hammad for bringing this issue to our attention under responsible disclosure.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907