CVE-2021-43062
Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2021-43062 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Fortinet FortiMailBrowse Fortinet / Fortinet FortiMail | CVE List | FortiMail 7.0.1, 7.0.0, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.11, 6.0.10, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBFortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)ExploitDB exploitby Braiant Giraldo VillaNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMFortinet FortiMail 7.0.1 - Cross-Site ScriptingCVSS 6.1
A cross-site scripting vulnerability in FortiMail may allow an unauthenticated attacker to perform an attack via specially crafted HTTP GET requests to the FortiGuard URI protection service.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patch or upgrade to a non-vulnerable version of Fortinet FortiMail.
Source: ProjectDiscovery