Reflected Cross Site Scripting Vulnerability in FortiAuthenticator by Fortinet
CVE-2022-35850
4.2MEDIUM
Summary
A vulnerability exists in FortiAuthenticator, allowing remote unauthenticated attackers to exploit improper script tag handling. This flaw can result in reflected cross site scripting (XSS) attacks via the 'reset-password' page. It affects several versions from 6.1 to 6.4.4, posing risks to users by potentially delivering malicious scripts.
Affected Version(s)
FortiAuthenticator 6.4.0 <= 6.4.4
FortiAuthenticator 6.3.0 <= 6.3.3
FortiAuthenticator 6.2.0 <= 6.2.2
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved