An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and non-authenticated attackers in the same network as the appliance to perform a stored cross site scripting attack (XSS) via injecting malicious payloads in different locations.
History

Mon, 17 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Mar 2025 13:30:00 +0000

Type Values Removed Values Added
Description An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and non-authenticated attackers in the same network as the appliance to perform a stored cross site scripting attack (XSS) via injecting malicious payloads in different locations.
First Time appeared Fortinet
Fortinet fortiwlc
Weaknesses CWE-79
CPEs cpe:2.3:a:fortinet:fortiwlc:8.3.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.6.0:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiwlc
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:F/RL:X/RC:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2025-03-17T13:52:53.619Z

Reserved: 2021-01-25T14:47:15.090Z

Link: CVE-2021-26087

cve-icon Vulnrichment

Updated: 2025-03-17T13:52:49.149Z

cve-icon NVD

Status : Received

Published: 2025-03-17T14:15:17.247

Modified: 2025-03-17T14:15:17.247

Link: CVE-2021-26087

cve-icon Redhat

No data.