<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Reflected XSS in the password reset page</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-275</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-04-11T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-04-11T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-04-11T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the &#34;reset-password&#34; page.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiAuthenticator 6.5 all versions are not affectedFortiAuthenticator version 6.4.0 through 6.4.6FortiAuthenticator version 6.3.0 through 6.3.3FortiAuthenticator 6.2 all versionsFortiAuthenticator 6.1 all versionsFortiAuthenticator 6.0 all versions are not affectedFortiAuthenticator 5.5 all versions are not affected
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiAuthenticator version 6.5.0 or abovePlease upgrade to FortiAuthenticator version 6.4.7 or abovePlease upgrade to FortiAuthenticator version 6.3.4 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank Leandro Barragan from SwordBytes for reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiAuthenticator" Type="Product Name">
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.4.6">FortiAuthenticator 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.4.5">FortiAuthenticator 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.4.4">FortiAuthenticator 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.4.3">FortiAuthenticator 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.4.2">FortiAuthenticator 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.4.1">FortiAuthenticator 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.4.0">FortiAuthenticator 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.3.3" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.3.3">FortiAuthenticator 6.3.3</FullProductName>
                </Branch>
                <Branch Name="6.3.2" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.3.2">FortiAuthenticator 6.3.2</FullProductName>
                </Branch>
                <Branch Name="6.3.1" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.3.1">FortiAuthenticator 6.3.1</FullProductName>
                </Branch>
                <Branch Name="6.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.3.0">FortiAuthenticator 6.3.0</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.2.2">FortiAuthenticator 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.2.1">FortiAuthenticator 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.2.0">FortiAuthenticator 6.2.0</FullProductName>
                </Branch>
                <Branch Name="6.1.3" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.1.3">FortiAuthenticator 6.1.3</FullProductName>
                </Branch>
                <Branch Name="6.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.1.2">FortiAuthenticator 6.1.2</FullProductName>
                </Branch>
                <Branch Name="6.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.1.1">FortiAuthenticator 6.1.1</FullProductName>
                </Branch>
                <Branch Name="6.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiAuthenticator-6.1.0">FortiAuthenticator 6.1.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Reflected XSS in the password reset page</Title>
        <cvrf:CVE>CVE-2022-35850</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiAuthenticator-6.4.6</ProductID>
                <ProductID>FortiAuthenticator-6.4.5</ProductID>
                <ProductID>FortiAuthenticator-6.4.4</ProductID>
                <ProductID>FortiAuthenticator-6.4.3</ProductID>
                <ProductID>FortiAuthenticator-6.4.2</ProductID>
                <ProductID>FortiAuthenticator-6.4.1</ProductID>
                <ProductID>FortiAuthenticator-6.4.0</ProductID>
                <ProductID>FortiAuthenticator-6.3.3</ProductID>
                <ProductID>FortiAuthenticator-6.3.2</ProductID>
                <ProductID>FortiAuthenticator-6.3.1</ProductID>
                <ProductID>FortiAuthenticator-6.3.0</ProductID>
                <ProductID>FortiAuthenticator-6.2.2</ProductID>
                <ProductID>FortiAuthenticator-6.2.1</ProductID>
                <ProductID>FortiAuthenticator-6.2.0</ProductID>
                <ProductID>FortiAuthenticator-6.1.3</ProductID>
                <ProductID>FortiAuthenticator-6.1.2</ProductID>
                <ProductID>FortiAuthenticator-6.1.1</ProductID>
                <ProductID>FortiAuthenticator-6.1.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>4.2</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:F/RL:U/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-275</URL>
                <Description>Reflected XSS in the password reset page</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>