CVE-2021-22122: XSS
Published Feb 8, 2021
·Updated
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.
Affected Software
2 affected components
Fortinet FortiWeb<=6.2.3
Fortinet FortiWeb>=6.3.0<=6.3.7
Event History
Feb 8, 2021
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22122?
CVE-2021-22122 has been classified as a high severity vulnerability.
2
How do I fix CVE-2021-22122?
To mitigate CVE-2021-22122, upgrade to FortiWeb versions 6.3.8 or later, or 6.2.4 or later.
3
Who is affected by CVE-2021-22122?
CVE-2021-22122 affects FortiWeb GUI interface versions 6.3.0 through 6.3.7 and any version before 6.2.4.
4
What type of attack is CVE-2021-22122 associated with?
CVE-2021-22122 is associated with reflected cross-site scripting (XSS) attacks.
5
Can CVE-2021-22122 be exploited remotely?
Yes, CVE-2021-22122 can be exploited by unauthenticated remote attackers.