CVE-2022-22304 MEDIUM

CVE-2022-22304

Vendor Fortinet
Product Fortinet FortiAuthenticator OutlookAgent
Published July 18, 2022
Last update October 22, 2024

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:X/RL:X/RC:X

What the vulnerability does

01Description

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

Key dates

02Disclosure timeline

July 18, 2022 CVE published
October 22, 2024 Record updated