PT-2021-7575 · Fortinet · Fortiwan

Published

2021-04-05

·

Updated

2022-04-13

·

CVE-2021-32585

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FortiWAN versions prior to 4.5.9
Description The issue is related to an improper neutralization of input during web page generation, which may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests. This could potentially enable a remote attacker to execute a spoofing attack by exploiting errors in the user interface's representation of information.
Recommendations For FortiWAN versions prior to 4.5.9, update to version 4.5.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation. Avoid using the web interface with untrusted input until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00105
CVE-2021-32585

Affected Products

Fortiwan