← back
CVE-2021-22122observed exploitation

CVE-2021-22122

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 11%
from disclosure to weapon
Published on NVDFeb 8
VulnCheck+1078d
exploitation probability
11%top 5% of all CVEs
observed exploitation
yesVulnCheck
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.