Headline
CVE-2021-42752: Fortiguard
A improper neutralization of input during web page generation (‘cross-site scripting’) in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim’s host via crafted HTTP requests
PSIRT Advisories
FortiWLM - reflected cross-site scripting vulnerability in cgi_bin handlers
Summary
An improper neutralization of input during web page generation (‘Cross-site Scripting’) vulnerability [CWE-79] in FortiWLM may allow an
authenticated user to perform an XSS attack via crafted HTTP GET requests.
Affected Products
FortiWLM version 8.6.1 and below
Solutions
Upgrade to FortiWLM version 8.6.2 or above.
Acknowledgement
Internally discovered and reported by Mattia Fecit of Fortinet Product Security team.