Stored Cross-Site Scripting Vulnerability in FortiOS by Fortinet
CVE-2021-43080
4.6MEDIUM
What is CVE-2021-43080?
FortiOS versions, including 7.2.0 and multiple iterations of 6.4.x and 7.0.x, possess a vulnerability that allows authenticated attackers to execute stored cross-site scripting (XSS) attacks. This occurs through improper input handling in the URI parameter located in the Threat Feed IP address section of Security Fabric External connectors, potentially compromising the safety of users interacting with affected systems.
Affected Version(s)
Fortinet FortiOS FortiOS 7.2.0, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.9, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0