CVE-2021-43062: XSS
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43062?
CVE-2021-43062 is a vulnerability in Fortinet FortiMail that allows an attacker to execute unauthorized code or commands through crafted HTTP GET requests.
How severe is CVE-2021-43062?
CVE-2021-43062 has a severity value of 6.1, which is considered medium.
Which versions of Fortinet FortiMail are affected by CVE-2021-43062?
Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, and version 6.3.7 and below are affected by CVE-2021-43062.
How can an attacker exploit CVE-2021-43062?
An attacker can exploit CVE-2021-43062 by sending carefully crafted HTTP GET requests to the vulnerable FortiMail server.
Are there any fixes or patches available for CVE-2021-43062?
Yes, Fortinet has released patches and updates to address the vulnerability. It is recommended to update to the latest version of Fortinet FortiMail.