Tracker / CVE-2022-23438
CVE-2022-23438
Medium 4.7
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
Affected products and versions
| fortinet | fortios · … → 6.4.9 |
|---|---|
| fortinet | fortios · 7.0.0 → 7.0.5 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.