Cross-Site Scripting Vulnerability in Fortinet FortiWeb Web Application Firewall
CVE-2021-36188
What is CVE-2021-36188?
A cross-site scripting vulnerability exists in Fortinet's FortiWeb web application firewall, affecting versions 6.4.1 and earlier as well as 6.3.15 and earlier. This flaw allows an attacker to inject malicious scripts through improperly neutralized input during web page generation. By exploiting this vulnerability, attackers can execute unauthorized code or commands via specially crafted GET parameters submitted to the login and error handler interfaces, posing significant risks to the integrity of affected systems.
Affected Version(s)
Fortinet FortiWeb FortiWeb 6.4.1, 6.4.0, 6.3.15, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.1, 6.3.0, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.1.2, 6.1.1, 6.1.0, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0