CVE-2021-43062
Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.
Una neutralización inapropiada de la entrada durante la generación de la página web ("cross-site scripting") en Fortinet FortiMail versiones 7.0.1 y 7.0.0, versiones 6.4.5 y anteriores, versiones 6.3.7 y anteriores, versiones 6.0.11 y anteriores, permiten a un atacante ejecutar código o comandos no autorizados por medio de peticiones HTTP GET diseñadas al servicio de protección URI de FortiGuard
Fortinet Fortimail version 7.0.1 suffers from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-10-28 CVE Reserved
- 2022-02-02 CVE Published
- 2022-02-18 First Exploit
- 2024-10-18 EPSS Updated
- 2024-10-22 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/50759 | 2022-02-18 | |
http://packetstormsecurity.com/files/166055/Fortinet-Fortimail-7.0.1-Cross-Site-Scripting.html | 2024-10-22 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fortiguard.com/advisory/FG-IR-21-185 | 2022-03-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortimail Search vendor "Fortinet" for product "Fortimail" | >= 6.2.0 < 6.2.8 Search vendor "Fortinet" for product "Fortimail" and version " >= 6.2.0 < 6.2.8" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortimail Search vendor "Fortinet" for product "Fortimail" | >= 6.4.0 < 6.4.6 Search vendor "Fortinet" for product "Fortimail" and version " >= 6.4.0 < 6.4.6" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortimail Search vendor "Fortinet" for product "Fortimail" | >= 7.0.0 < 7.0.2 Search vendor "Fortinet" for product "Fortimail" and version " >= 7.0.0 < 7.0.2" | - |
Affected
|