First published: Mon Feb 08 2021(Updated: )
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWeb | <=6.2.3 | |
Fortinet FortiWeb | >=6.3.0<=6.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22122 has been classified as a high severity vulnerability.
To mitigate CVE-2021-22122, upgrade to FortiWeb versions 6.3.8 or later, or 6.2.4 or later.
CVE-2021-22122 affects FortiWeb GUI interface versions 6.3.0 through 6.3.7 and any version before 6.2.4.
CVE-2021-22122 is associated with reflected cross-site scripting (XSS) attacks.
Yes, CVE-2021-22122 can be exploited by unauthenticated remote attackers.