CVE-2022-43952: Fortinet FortiADC
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC version 7.1.1 and below, version 7.0.3 and below, version 6.2.5 and below may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.
Affected products
- Fortinet FortiADC: from 6.2.0, before 6.2.6 (fixed in 6.2.6); from 7.0.0, before 7.0.4 (fixed in 7.0.4); from 7.1.0, before 7.1.2 (fixed in 7.1.2)
Published 2023-04-11. Last modified 2026-06-17.