Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4343-wxmv-4jg6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of the device.

An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of the device.

EPSS

Процентиль: 41%
0.00192
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.1
nvd
больше 4 лет назад

An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of the device.

EPSS

Процентиль: 41%
0.00192
Низкий

Дефекты

CWE-79