EIP-2026-101282
PRE-CVEFortinet FortiWeb (Multiple Appliances) - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101282. PoCs published by Benjamin Kunz Mejri.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in multiple Fortinet FortiWeb appliances by injecting malicious JavaScript via the 'redir' and 'mkey' parameters in the URL. The payload uses an iframe with an onload event to trigger an alert, confirming the vulnerability.
Description
Fortinet FortiWeb (Multiple Appliances) - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in multiple Fortinet FortiWeb appliances by injecting malicious JavaScript via the 'redir' and 'mkey' parameters in the URL. The payload uses an iframe with an onload event to trigger an alert, confirming the vulnerability.