CVE-2021-36191: Medium severity fortinet fortiweb vulnerability
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this Fortinet FortiWeb vulnerability?
The vulnerability ID of this Fortinet FortiWeb vulnerability is CVE-2021-36191.
What is the severity level of CVE-2021-36191?
The severity level of CVE-2021-36191 is medium with a score of 5.4.
Which versions of Fortinet FortiWeb are affected by CVE-2021-36191?
Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below, 6.2.6 and below, 6.1.2 and below, and 6.0.7 and below are affected by CVE-2021-36191.
What is the impact of CVE-2021-36191?
CVE-2021-36191 allows an attacker to use the Fortinet FortiWeb device as a proxy by exploiting crafted GET parameters in requests to error handlers.
Is there a fix available for CVE-2021-36191?
Yes, it is recommended to upgrade Fortinet FortiWeb to a version that is not affected by CVE-2021-36191.