CVE-2021-36188: XSS
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted GET parameters in requests to login and error handlers
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36188?
CVE-2021-36188 is a vulnerability that allows an attacker to execute unauthorized code or commands through crafted GET parameters in requests to login and error handlers in Fortinet FortiWeb versions 6.4.1 and below, 6.3.15 and below.
How severe is CVE-2021-36188?
CVE-2021-36188 has a severity rating of 6.1 (medium).
What software versions are affected by CVE-2021-36188?
Fortinet FortiWeb versions 6.4.1 and below, 6.3.15 and below are affected by CVE-2021-36188.
How can an attacker exploit CVE-2021-36188?
An attacker can exploit CVE-2021-36188 by sending crafted GET parameters in requests to login and error handlers in Fortinet FortiWeb.
Is there a fix available for CVE-2021-36188?
To mitigate CVE-2021-36188, it is recommended to upgrade Fortinet FortiWeb to a version higher than 6.4.1 or 6.3.15, if available.