imPC@ndo IT

Tracker / CVE-2022-40680

CVE-2022-40680

Medium 4.0

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via storing malicious payloads in replacement messages.

Affected products and versions

fortinet fortios · 6.0.7 → 6.0.15
fortinet fortios · 6.2.2 → 6.2.12
fortinet fortios · 6.4.0 → 6.4.9
fortinet fortios · 7.0.0 → 7.0.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References