5.4
CVSSv3

CVE-2022-42471

Published: 03/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 up to and including 7.0.2, FortiWeb version 6.4.0 up to and including 6.4.2, FortiWeb version 6.3.6 up to and including 6.3.20 may allow an authenticated and remote malicious user to inject arbitrary headers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortiweb 6.4.0

fortinet fortiweb 6.4.1

fortinet fortiweb 6.4.2

fortinet fortiweb 7.0.0

fortinet fortiweb 7.0.1

fortinet fortiweb 7.0.2

fortinet fortiweb