CVE-2021-43062
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 12.94% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- fortinet/fortimail
- Source
- psirt@fortinet.com
References
- http://packetstormsecurity.com/files/166055/Fortinet-Fortimail-7.0.1-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-21-185Vendor Advisory
- http://packetstormsecurity.com/files/166055/Fortinet-Fortimail-7.0.1-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-21-185Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.