CVE-2022-40679 PUBLISHED CVSS 4.199999809265137 MEDIUM

An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password" page.

EPSS 0.12% · 31.6th percentile

Risk Scores

CVSS v3.1
4.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:F/RL:U/RC:C
EPSS Score
0.12%
31.6th percentile

Affected Products

VendorProductVersions
FortinetFortiAuthenticator6.4.0, 6.3.0, 6.2.0

Timeline

References

…and 2 more

Open in Interactive Console →