CVE-2022-41334 is a cross-site scripting (XSS) vulnerability affecting FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3. A remote, unauthenticated attacker can exploit this by manipulating the "redir" parameter when the "Sign in with FortiCloud" button is clicked. Rated as Medium severity (CVSS 6.1), the attack requires user interaction but could lead to information disclosure and integrity issues. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, <= 7.0.7CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.2.0, <= 7.2.3CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.