CVE-2021-22122
Fortinet FortiWeb Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2021-22122 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 23, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
FortiWebBrowse Fortinet / FortiWeb | VulnCheck | Version data not supplied | |
Fortinet FortiWebBrowse Fortinet / Fortinet FortiWeb | CVE List | FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMFortiWeb - Cross Site ScriptingCVSS 6.1
FortiWeb 6.3.0 through 6.3.7 and versions before 6.2.4 contain an unauthenticated cross-site scripting vulnerability. Improper neutralization of input during web page generation can allow a remote attacker to inject malicious payload in vulnerable API end-points.
Impact
Successful exploitation of this vulnerability can result in the compromise of sensitive user information, session hijacking.
Remediation
Apply the latest security patches or updates provided by Fortinet to fix the XSS vulnerability in FortiWeb.
Source: ProjectDiscovery