Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-22304


An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.


Published

2022-07-18T17:15:08.667

Last Modified

2024-11-21T06:46:36.213

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiauthenticator_agent_for_microsoft_outlook_web_access 2.1 Yes
Application fortinet fortiauthenticator_agent_for_microsoft_outlook_web_access 2.2 Yes

References