CVE-2021-43080
published 2022-09-06CVE-2021-43080: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.37%
29.3th percentile
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet_fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.0 < 6.4.10 | 6.4.10 |
| fortinet | fortios | >= 7.0.0 < 7.0.6 | 7.0.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9rfg-v9qp-56r5: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7
ghsa_unreviewed·2022-09-07
CVE-2021-43080 [MEDIUM] CWE-79 GHSA-9rfg-v9qp-56r5: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors.
Fortinet
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version...
vendor_fortinet·2022-09-06·CVSS 4.6
CVE-2021-43080 [MEDIUM] CWE-79 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version...
FG-IR-21-222: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version...
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors.
CVEs: CVE-2021-43080
CWEs: CWE-79
CVSS: 4.6 (medium)
Affected products: FortiOS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-06
Published