Lucene search

K
fortinetFortiGuard LabsFG-IR-22-166
HistoryFeb 16, 2023 - 12:00 a.m.

FortiAnalyzer - XSS vulnerability due to AngularJS Client-Side Template injection

2023-02-1600:00:00
FortiGuard Labs
www.fortiguard.com
39
fortianalyzer
xss vulnerability
angularjs
client-side template injection
cwe-79
remote unauthenticated attacker
stored cross site scripting
fortiweb
attack event logview

EPSS

0.001

Percentile

49.8%

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parameter observed in the FortiWeb attack event logview in FortiAnalyzer.

EPSS

0.001

Percentile

49.8%

Related for FG-IR-22-166