Lucene search

K
cvelistFortinetCVELIST:CVE-2021-24021
HistoryOct 06, 2021 - 9:45 a.m.

CVE-2021-24021

2021-10-0609:45:59
fortinet
www.cve.org
4
cve-2021-24021
fortianalyzer
input neutralization
cross site scripting

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:F

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

33.0%

An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below and 6.0.10 and below may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the column settings of Logview in FortiAnalyzer, should the attacker be able to obtain that POST request, via other, hypothetical attacks.

CNA Affected

[
  {
    "product": "Fortinet FortiAnalyzer",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiAnalyzer 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.10, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:F

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

33.0%

Related for CVELIST:CVE-2021-24021