Lucene search

K
fortinetFortiGuard LabsFG-IR-21-185
HistoryFeb 01, 2022 - 12:00 a.m.

FortiMail - reflected cross-site scripting vulnerability in FortiGuard URI protection

2022-02-0100:00:00
FortiGuard Labs
www.fortiguard.com
18
fortimail
xss
vulnerability
fortiguard
uri protection
cwe-79
http
get
request
service
attack

EPSS

0.006

Percentile

78.2%

An improper neutralization of input during web page generation vulnerability (‘Cross-site Scripting’) [CWE-79] in FortiMail may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests to the FortiGuard URI protection service.

EPSS

0.006

Percentile

78.2%