Home

Description

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler

PUBLISHED Reserved 2021-09-13 | Published 2021-12-08 | Updated 2024-10-25 | Assigner fortinet




MEDIUM: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RL:X/RC:C

Problem types

Execute unauthorized code or commands

Product status

FortiWeb 6.4.1, 6.4.0
affected

References

fortiguard.com/advisory/FG-IR-21-139

fortiguard.com/advisory/FG-IR-21-139

cve.org (CVE-2021-41015)

nvd.nist.gov (CVE-2021-41015)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.