CVE-2021-43081

MEDIUM

FortiOS <7.0.3,6.4.8,6.2.10,6.0.14-6.0.0 - XSS

Title source: llm
STIX 2.1

Description

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-21-230

Scores

CVSS v3 6.1
EPSS 0.0068
EPSS Percentile 71.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
fortinet/fortios 6.0.0 - 6.0.14
fortinet/fortiproxy 2.0.0 - 2.0.8
Published May 11, 2022
Tracked Since Feb 18, 2026