Stored Cross-Site Scripting Vulnerability in FortiOS by Fortinet
CVE-2021-43080
4.6MEDIUM
Summary
FortiOS versions, including 7.2.0 and multiple iterations of 6.4.x and 7.0.x, possess a vulnerability that allows authenticated attackers to execute stored cross-site scripting (XSS) attacks. This occurs through improper input handling in the URI parameter located in the Threat Feed IP address section of Security Fabric External connectors, potentially compromising the safety of users interacting with affected systems.
Affected Version(s)
Fortinet FortiOS FortiOS 7.2.0, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.9, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved