ZeroHour

CVE-2022-22304

CVSS 3.1
6.1 medium
EPSS
<1%p44
Published
()
Modified
Description

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

Vendors
fortinet
Products
fortiauthenticator agent for microsoft outlook web access
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.