Lucene search

K
nvd[email protected]NVD:CVE-2022-39950
HistoryNov 02, 2022 - 12:15 p.m.

CVE-2022-39950

2022-11-0212:15:55
CWE-79
web.nvd.nist.gov
1
improper input neutralization
web page generation
cwe-79
fortimanager
fortianalyzer
xss attack
low privilege
ckeditor
cve-2020-9281

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

0.002 Low

EPSS

Percentile

53.2%

An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor “protected” comment as described in CVE-2020-9281.

Affected configurations

NVD
Node
fortinetfortianalyzerRange6.0.06.2.9
OR
fortinetfortianalyzerRange6.4.06.4.8
OR
fortinetfortianalyzerRange7.0.07.0.4
OR
fortinetfortimanagerRange6.0.06.2.9
OR
fortinetfortimanagerRange6.4.06.4.8
OR
fortinetfortimanagerRange7.0.07.0.4

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

0.002 Low

EPSS

Percentile

53.2%