Stored Cross-Site Scripting Vulnerability in FortiOS by Fortinet
CVE-2021-43080

4.6MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
6 September 2022

Summary

FortiOS versions, including 7.2.0 and multiple iterations of 6.4.x and 7.0.x, possess a vulnerability that allows authenticated attackers to execute stored cross-site scripting (XSS) attacks. This occurs through improper input handling in the URI parameter located in the Threat Feed IP address section of Security Fabric External connectors, potentially compromising the safety of users interacting with affected systems.

Affected Version(s)

Fortinet FortiOS FortiOS 7.2.0, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.9, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.