Cross-Site Scripting Vulnerability in Fortinet FortiWeb Web Application Firewall
CVE-2021-36188
Summary
A cross-site scripting vulnerability exists in Fortinet's FortiWeb web application firewall, affecting versions 6.4.1 and earlier as well as 6.3.15 and earlier. This flaw allows an attacker to inject malicious scripts through improperly neutralized input during web page generation. By exploiting this vulnerability, attackers can execute unauthorized code or commands via specially crafted GET parameters submitted to the login and error handler interfaces, posing significant risks to the integrity of affected systems.
Affected Version(s)
Fortinet FortiWeb FortiWeb 6.4.1, 6.4.0, 6.3.15, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.1, 6.3.0, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.1.2, 6.1.1, 6.1.0, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved