### [CVE-2022-35850](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-35850) ![](https://img.shields.io/static/v1?label=Product&message=FortiAuthenticator&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=6.4.0%3C%3D%206.4.4%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Execute%20unauthorized%20code%20or%20commands&color=brighgreen) ### Description An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password" page. ### POC #### Reference No PoCs from references. #### Github - https://github.com/lean0x2F/lean0x2f.github.io