Lucene search

K
fortinetFortiGuard LabsFG-IR-21-248
HistoryDec 06, 2022 - 12:00 a.m.

Protect

2022-12-0600:00:00
FortiGuard Labs
www.fortiguard.com
37
fortios
stored xss attack
input neutralization
web page generation
cross-site scripting
cwe-79
privileged attacker
malicious payloads

EPSS

0.001

Percentile

22.9%

A improper neutralization of input during web page generation (‘cross-site scripting’) [CWE-79] in FortiOS may allow a privileged attacker to perform a stored XSS attack via storing malicious payloads in replacement messages.

EPSS

0.001

Percentile

22.9%

Related for FG-IR-21-248