CVE-2021-32585: XSS
Published Apr 6, 2022
·Updated
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests.
Affected Software
1 affected component
Fortinet FortiWan<4.5.9
Event History
Apr 6, 2022
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-32585?
CVE-2021-32585 is classified as a moderate severity vulnerability in FortiWAN.
2
How do I fix CVE-2021-32585?
To fix CVE-2021-32585, upgrade FortiWAN to version 4.5.9 or later.
3
What software is affected by CVE-2021-32585?
CVE-2021-32585 affects FortiWAN versions prior to 4.5.9.
4
What type of attack does CVE-2021-32585 enable?
CVE-2021-32585 enables an attacker to perform a stored cross-site scripting attack.
5
What causes the vulnerability in CVE-2021-32585?
CVE-2021-32585 is caused by improper neutralization of input during web page generation.