Cross-Site Scripting Vulnerability in Fortinet FortiEDR
CVE-2022-29057
5.4MEDIUM
What is CVE-2022-29057?
The vulnerability involves improper handling of user input during the web page generation process in Fortinet's FortiEDR. This flaw creates an opportunity for a remote, authenticated attacker to execute a reflected cross-site scripting attack. By injecting malicious payloads into various endpoints of the Management Console, the attacker can manipulate user sessions, redirect users to harmful sites, or steal sensitive data. This issue affects specific versions of FortiEDR, highlighting the importance of timely patching and security measures.
Affected Version(s)
Fortinet FortiEDR FortiEDR 5.0.3, 5.0.2, 5.0.1, 5.0.0, 4.0.0