A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the login webpage.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2021-12-08T13:16:29

Updated: 2024-08-04T03:47:13.346Z

Reserved: 2021-10-28T00:00:00

Link: CVE-2021-43063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-08T14:15:09.587

Modified: 2021-12-09T19:58:03.270

Link: CVE-2021-43063

cve-icon Redhat

No data.