Record summary

CVE-2021-22122 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 23, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE ListFortiWeb 6.3.0 through 6.3.7 and version before 6.2.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMFortiWeb - Cross Site ScriptingCVSS 6.1

FortiWeb 6.3.0 through 6.3.7 and versions before 6.2.4 contain an unauthenticated cross-site scripting vulnerability. Improper neutralization of input during web page generation can allow a remote attacker to inject malicious payload in vulnerable API end-points.

Impact

Successful exploitation of this vulnerability can result in the compromise of sensitive user information, session hijacking.

Remediation

Apply the latest security patches or updates provided by Fortinet to fix the XSS vulnerability in FortiWeb.

WeaknessesCWE-79
Authorsdwisiswant0
Template tagscve2021cvefortiwebxssfortinetvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Shodan: http.title:"fortiweb - "
FOFA: title="fortiweb - "
Google: intitle:"fortiweb - "

Source: ProjectDiscovery

References

2