← back
CVE-2021-43062medium

CVE-2021-43062

53Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 6.1epss 13%
from disclosure to weapon16 days
Published on NVDFeb 2
1st PoC+16d
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RL:X/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.