CVE-2021-26092: [SSL VPN Portal] Reflected XSS via the error request
Failure to sanitize input in the SSL VPN web portal may allow a remote unauthenticated attacker to perform a reflected Cross-site Scripting (XSS) attack by sending a request to the error page with malicious GET parameters.
Other sources
Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 may allow a remote unauthenticated attacker to perform a reflected Cross-site Scripting (XSS) attack by sending a request to the error page with malicious GET parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26092?
The severity of CVE-2021-26092 is medium.
What is the affected software for CVE-2021-26092?
The affected software for CVE-2021-26092 includes FortiOS versions 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, and 6.4.0 through 6.4.4, as well as FortiProxy versions 1.2.0 through 1.2.9 and 2.0.0 through 2.0.1.
How does CVE-2021-26092 affect Fortinet FortiOS?
CVE-2021-26092 affects FortiOS by failing to sanitize input in the SSL VPN web portal, which may allow a remote unauthenticated attacker to perform malicious actions.
How does CVE-2021-26092 affect Fortinet FortiProxy?
CVE-2021-26092 affects FortiProxy by failing to sanitize input in the SSL VPN web portal, which may allow a remote unauthenticated attacker to perform malicious actions.
How can I fix CVE-2021-26092?
To fix CVE-2021-26092, it is recommended to update FortiOS and FortiProxy to the latest patched versions provided by Fortinet.