CVE-2021-26087
Severity
6.1MEDIUM
EPSS
0.1%
top 83.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 17
Description
An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and non-authenticated attackers in the same network as the appliance to perform a stored cross site scripting attack (XSS) via injecting malicious payloads in different locations.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages2 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Fortinet▶
An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, versi...↗2025-03-17