Reflected cross-site scripting vulnerability in FortiGuard URI protection

Summary

An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in FortiMail may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests to the FortiGuard URI protection service.

Affected Products

FortiMail version 7.0.1 and below
FortiMail version 6.4.5 and below
FortiMail version 6.2.7 and below

Solutions

Upgrade to FortiMail version 7.0.2 or above
Upgrade to FortiMail version 6.4.6 or above
Upgrade to FortiMail version 6.2.8 or above

Acknowledgement

Fortinet is pleased to thank Braiant Giraldo Villa for reporting this vulnerability under responsible disclosure.

Timeline

2022-02-01: Initial publication