Cross-Site Scripting Vulnerability in Fortinet FortiWLM Products
CVE-2021-41029

6.4MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
8 December 2021

Summary

An improper neutralization of input during web page generation in Fortinet FortiWLM allows attackers to inject malicious JavaScript code. This code can be stored on the device and executed through specially crafted HTTP requests, potentially compromising the security of users interacting with the affected system. This vulnerability highlights the importance of robust input validation and the implementation of security best practices to prevent unauthorized script execution.

Affected Version(s)

Fortinet FortiWLM FortiWLM 8.6.1, 8.6.0, 8.5.2, 8.5.1, 8.5.0, 8.4.2, 8.4.1, 8.4.0, 8.3.2, 8.3.1, 8.3.0, 8.2.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.