CVE-2021-43062
published 2022-02-02CVE-2021-43062: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below…
PriorityP346medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
12.94%
95.9th percentile
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiguard | — | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | >= 6.2.0 < 6.2.8 | 6.2.8 |
| fortinet | fortimail | >= 6.4.0 < 6.4.6 | 6.4.6 |
| fortinet | fortimail | >= 7.0.0 < 7.0.2 | 7.0.2 |
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortimail | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for HTTP GET requests targeting the /fmlurlsvc/ endpoint with a crafted `url` parameter containing XSS payloads (e.g., SVG onload vectors). ↗
- →Detect responses from /fmlurlsvc/ that reflect both a <script> tag and the string 'FortiMail Click Protection' in the HTML body with HTTP 200 status. ↗
- →Use Google dork `inurl:/fmlurlsvc/` to identify exposed FortiMail instances vulnerable to this XSS. ↗
- →Use FOFA queries `title="fortimail"` or `fortimail && port=443` to identify internet-exposed FortiMail instances. ↗
- ·The XSS is reflected and unauthenticated — no session or credentials are required to trigger the payload via the FortiGuard URI protection service endpoint. ↗
- ·Affected versions span multiple branches: FortiMail 7.0.1 and 7.0.0, 6.4.5 and below, 6.3.7 and below, and 6.0.11 and below — detection rules should not be scoped to a single version. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6fhp-jhwr-cwgh: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7
ghsa_unreviewed·2022-02-08
CVE-2021-43062 [MEDIUM] CWE-79 GHSA-6fhp-jhwr-cwgh: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.
Fortinet
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0...
vendor_fortinet·2022-02-02·CVSS 6.1
CVE-2021-43062 [MEDIUM] CWE-79 A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0...
FG-IR-21-185: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0...
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.
CVEs: CVE-2021-43062
CWEs: CWE-79
CVSS: 6.1 (medium)
Affected products: FortiGuard, FortiMail, Fortinet
No detection rules found.
Exploit-DB
Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
exploitdb·2022-02-18·CVSS 6.1
CVE-2021-43062 [MEDIUM] Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
---
# Exploit Title: Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
# Google Dork: inurl:/fmlurlsvc/
# Date: 01-Feb-2022
# Exploit Author: Braiant Giraldo Villa
# Contact: @iron_fortress (Twitter)
# Vendor Homepage: https://www.fortinet.com/products/email-security
# Software Link: https://fortimail.fortidemo.com/m/webmail/ (Vendor Demo Online)
# Version:
# FortiMail version 7.0.1 and below
# FortiMail version 6.4.5 and below
# FortiMail version 6.2.7 and below
# CVE: CVE-2021-43062 (https://www.fortiguard.com/psirt/FG-IR-21-185)
1. Description:
An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in FortiMail may allow an unauthenticated attacker to
Nuclei
Fortinet FortiMail 7.0.1 - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2021-43062 [MEDIUM] Fortinet FortiMail 7.0.1 - Cross-Site Scripting
Fortinet FortiMail 7.0.1 - Cross-Site Scripting
A cross-site scripting vulnerability in FortiMail may allow an unauthenticated attacker to perform an attack via specially crafted HTTP GET requests to the FortiGuard URI protection service.
Template:
id: CVE-2021-43062
info:
name: Fortinet FortiMail 7.0.1 - Cross-Site Scripting
author: ajaysenr
severity: medium
description: A cross-site scripting vulnerability in FortiMail may allow an unauthenticated attacker to perform an attack via specially crafted HTTP GET requests to the FortiGuard URI protection service.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking, defacement, or theft of sens
2022-02-02
Published