Reflected cross-site scripting vulnerability in FortiGuard URI protection
Summary
An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in FortiMail may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests to the FortiGuard URI protection service.
Affected Products
FortiMail version 7.0.1 and below
FortiMail version 6.4.5 and below
FortiMail version 6.2.7 and below
Solutions
Upgrade to FortiMail version 7.0.2 or above
Upgrade to FortiMail version 6.4.6 or above
Upgrade to FortiMail version 6.2.8 or above
Acknowledgement
Fortinet is pleased to thank Braiant Giraldo Villa for reporting this vulnerability under responsible disclosure.Timeline
2022-02-01: Initial publication