Vulnerability Details CVE-2022-38379
Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.8%
CVSS Severity
CVSS v3 Score 3.5
Products affected by CVE-2022-38379
-
cpe:2.3:a:fortinet:fortisoar:7.0.0
-
cpe:2.3:a:fortinet:fortisoar:7.0.1
-
cpe:2.3:a:fortinet:fortisoar:7.0.2
-
cpe:2.3:a:fortinet:fortisoar:7.0.3
-
cpe:2.3:a:fortinet:fortisoar:7.2.0