An improper neutralization of input during web page generation vulnerability (‘Cross-site Scripting’) [CWE-79] in FortiMail may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests to the FortiGuard URI protection service.