Vulnerability Details CVE-2022-22304
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.7%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2022-22304
-
cpe:2.3:a:fortinet:fortiauthenticator_agent_for_microsoft_outlook_web_access:2.1
-
cpe:2.3:a:fortinet:fortiauthenticator_agent_for_microsoft_outlook_web_access:2.2