VYPR
Low severity3.5NVD Advisory· Published Dec 6, 2022· Updated Jun 17, 2026

CVE-2022-38379

CVE-2022-38379

Description

Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR.

Affected products

4
  • cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:*range: >=7.0.0,<=7.0.3
    • cpe:2.3:a:fortinet:fortisoar:7.2.0:*:*:*:*:*:*:*
    • (no CPE)range: 7.0.0-7.0.3, 7.2.0
    • (no CPE)range: 7.2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.