PT-2021-7575 · Fortinet · Fortiwan
Published
2021-04-05
·
Updated
2022-04-13
·
CVE-2021-32585
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FortiWAN versions prior to 4.5.9
Description
The issue is related to an improper neutralization of input during web page generation, which may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests. This could potentially enable a remote attacker to execute a spoofing attack by exploiting errors in the user interface's representation of information.
Recommendations
For FortiWAN versions prior to 4.5.9, update to version 4.5.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation. Avoid using the web interface with untrusted input until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiwan