Cross-Site Scripting Vulnerability in Fortinet FortiWeb Web Application Firewall
CVE-2021-36188

6.1MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
8 December 2021

Summary

A cross-site scripting vulnerability exists in Fortinet's FortiWeb web application firewall, affecting versions 6.4.1 and earlier as well as 6.3.15 and earlier. This flaw allows an attacker to inject malicious scripts through improperly neutralized input during web page generation. By exploiting this vulnerability, attackers can execute unauthorized code or commands via specially crafted GET parameters submitted to the login and error handler interfaces, posing significant risks to the integrity of affected systems.

Affected Version(s)

Fortinet FortiWeb FortiWeb 6.4.1, 6.4.0, 6.3.15, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.1, 6.3.0, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.1.2, 6.1.1, 6.1.0, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.