CVE-2021-24021 MEDIUM

CVE-2021-24021

Vendor Fortinet
Product Fortinet FortiAnalyzer
Published October 6, 2021
Last update October 25, 2024

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:F/RL:X/RC:X

What the vulnerability does

01Description

An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below and 6.0.10 and below may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the column settings of Logview in FortiAnalyzer, should the attacker be able to obtain that POST request, via other, hypothetical attacks.

Key dates

02Disclosure timeline

October 6, 2021 CVE published
October 25, 2024 Record updated