Stored Cross-Site Scripting Vulnerability in FortiAnalyzer by Fortinet
CVE-2021-24021
What is CVE-2021-24021?
FortiAnalyzer contains an improper neutralization of input vulnerability that can allow a remote authenticated attacker to execute a stored cross-site scripting attack. This issue arises in the column settings of the Logview feature, whereby an attacker could potentially manipulate a POST request to inject malicious scripts, leading to unauthorized actions or data exposure upon the execution of the compromised code in a victim's browser.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fortinet FortiAnalyzer FortiAnalyzer 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.10, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved