Reflected Cross Site Scripting Vulnerability in FortiWeb's GUI Interface by Fortinet
CVE-2021-22122

6.1MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
8 February 2021

What is CVE-2021-22122?

An improper neutralization of input in web page generation within the FortiWeb GUI interface allows unauthenticated remote attackers to execute a reflected cross site scripting attack. These attackers can inject malicious payloads through various vulnerable API endpoints. This vulnerability affects FortiWeb versions from 6.3.0 to 6.3.7 and those prior to 6.2.4, emphasizing the necessity for timely updates and robust input validation practices.

Affected Version(s)

Fortinet FortiWeb FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4

References

EPSS Score

62% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.