Lucene search

K
fortinetFortiGuard LabsFG-IR-22-234
HistoryNov 01, 2022 - 12:00 a.m.

FortiADC - WAF XSS Injection Bypass

2022-11-0100:00:00
FortiGuard Labs
www.fortiguard.com
25
fortiadc
waf
injection

EPSS

0.002

Percentile

55.0%

An improper handling of malformed request vulnerability [CWE-228] in FortiADC may allow a remote attacker without privileges to bypass some Web Application Firewall (WAF) protection such as the SQL Injection and XSS filters via a malformed HTTP request.

EPSS

0.002

Percentile

55.0%

Related for FG-IR-22-234