S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-43062 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Fortinet FortiMail affects v. 7.0.1 and 7.0.0, 6.4.5 and below, 6.3.7 and below, 6.0.11 and below.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-43062
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Fortinet FortiMailby Fortinet
FortiMail 7.0.1, 7.0.0, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.11, 6.0.10, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0
Updated Aug 21, 2026View on NVD →
Detail

Fortinet FortiMail is a powerful email security solution that is designed to protect organizations from advanced email threats such as phishing, spam, malware, and other email-borne attacks. FortiMail is used by large enterprises, service providers, government agencies, and educational institutions to secure their email communication and ensure compliance with regulatory requirements. The product offers end-to-end email encryption, real-time threat monitoring, advanced reporting, and flexible deployment options.

In recent news, Fortinet FortiMail has been found vulnerable to a critical cross-site scripting (XSS) vulnerability, identified as CVE-2021-43062. The issue lies in the improper neutralization of input during web page generation, which can allow malicious actors to execute unauthorized code or commands using crafted HTTP GET requests to the FortiGuard URI protection service. This vulnerability affects FortiMail versions 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, and version 6.0.11 and below.

This vulnerability can have serious consequences if exploited by attackers. It can allow them to gain unauthorized access to sensitive information stored or transmitted through FortiMail. Attackers can also use this vulnerability to launch further attacks on the organization's network and compromise other systems. It is a severe threat that requires immediate attention and remediation by organizations using FortiMail.

In conclusion, vulnerabilities like CVE-2021-43062 can pose a significant threat to organizations using Fortinet FortiMail. It is essential to take the necessary precautions to protect against such vulnerabilities and ensure the security of your digital assets. At s4e.io, we provide a platform that enables organizations to quickly and easily identify vulnerabilities in their digital assets and take appropriate action to prevent security breaches. Our pro features include advanced scanning, reporting, and remediation tools that ensure all your digital assets are secure and compliant. Stay secure with s4e.io.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations can take the following precautions:

  • Upgrade to the latest version of Fortinet FortiMail, which contains a patch for this vulnerability.
  • Implement strict input validation and filtering on FortiMail to prevent malicious inputs from being processed.
  • Block all untrusted sources of HTTP GET requests to the FortiGuard URI protection service.
  • Deploy a web application firewall (WAF) to detect and block XSS attacks targeting FortiMail.
  • Monitor FortiMail logs for any unusual activity or suspicious requests that could indicate an unauthorized breach attempt.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-43062 scanner - Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail | S4E