CVE-2021-43081: XSS
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43081?
CVE-2021-43081 is an improper neutralization of input during web page generation vulnerability in FortiOS and FortiProxy products.
Which versions of FortiOS are affected by CVE-2021-43081?
FortiOS versions 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, and 6.0.14 to 6.0.0 are affected by CVE-2021-43081.
Which versions of FortiProxy are affected by CVE-2021-43081?
FortiProxy versions 7.0.1 and below, and 2.0.7 to 2.0.0 are affected by CVE-2021-43081.
What is the severity of CVE-2021-43081?
CVE-2021-43081 has a severity rating of medium.
How can an attacker exploit CVE-2021-43081?
An unauthenticated attacker may exploit CVE-2021-43081 through the web filter override form in FortiOS and FortiProxy, potentially leading to information disclosure or other attacks.