Reflected Cross Site Scripting Vulnerability in FortiWeb's GUI Interface by Fortinet
CVE-2021-22122
6.1MEDIUM
Summary
An improper neutralization of input in web page generation within the FortiWeb GUI interface allows unauthenticated remote attackers to execute a reflected cross site scripting attack. These attackers can inject malicious payloads through various vulnerable API endpoints. This vulnerability affects FortiWeb versions from 6.3.0 to 6.3.7 and those prior to 6.2.4, emphasizing the necessity for timely updates and robust input validation practices.
Affected Version(s)
Fortinet FortiWeb FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved