NA

CVE-2022-30304

Published: 16/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions before 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated malicious user to perform a stored cross site scripting (XSS) attack via the URL parameter observed in the FortiWeb attack event logview in FortiAnalyzer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortianalyzer

fortinet fortianalyzer 7.2.0

fortinet fortianalyzer 7.2.1