imPC@ndo IT

Tracker / CVE-2022-22304

CVE-2022-22304

Medium 6.1

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

Affected products and versions

fortinet fortiauthenticator_agent_for_microsoft_outlook_web_access

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References