FortiAuthenticator - XSS vulnerability in OWA login page
Summary
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Affected Products
FortiAuthenticator Agent for Microsoft OWA version 2.2,
FortiAuthenticator Agent for Microsoft OWA version 2.1.
Solutions
Please upgrade to FortiAuthenticator Agent for Microsoft OWA version 2.3 or above.