Vulnerability Description
Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortianalyzer | < 6.2.8 |
| Fortinet | Fortimanager | < 6.2.8 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/advisory/FG-IR-21-054Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-21-054Vendor Advisory
FAQ
What is CVE-2021-32597?
CVE-2021-32597 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote auth...
How severe is CVE-2021-32597?
CVE-2021-32597 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32597?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortianalyzer, Fortinet Fortimanager.