Stored Cross-Site Scripting Vulnerability in FortiWAN by Fortinet
CVE-2021-32585

7.2HIGH

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
6 April 2022

Summary

An input validation flaw in FortiWAN prior to version 4.5.9 allows attackers to inject malicious scripts into web pages through specially crafted HTTP requests. This vulnerability can lead to stored cross-site scripting attacks, compromising user data and overall web application security. Implementing proper input sanitization and updating to the latest version is essential to mitigate this risk.

Affected Version(s)

Fortinet FortiWAN FortiWAN before 4.5.9

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.