Home
MEDIUM: 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RL:X/RC:C FortiWeb 6.4.1, 6.4.0
affected
Description
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler
Problem types
Execute unauthorized code or commands
Product status
References
fortiguard.com/advisory/FG-IR-21-139
fortiguard.com/advisory/FG-IR-21-139
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.