PoC Index

CVE-2021-43062

MEDIUM 6.1EPSS 12.9%

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
12.94% chance of exploitation in the next 30 days, 96th percentile
Nuclei
medium · CWE-79
Published
2022-02-02
Updated
2024-10-22

Proof-of-concept exploits (1)

Nuclei templates (1)

ExploitDB entries (1)

References

Related