An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-30033 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Tue, 22 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2024-10-22T20:54:00.161Z

Reserved: 2021-10-28T00:00:00

Link: CVE-2021-43080

cve-icon Vulnrichment

Updated: 2024-08-04T03:47:13.467Z

cve-icon NVD

Status : Modified

Published: 2022-09-06T16:15:08.407

Modified: 2024-11-21T06:28:39.213

Link: CVE-2021-43080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.