S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-22122 Scanner

CVE-2021-22122 scanner - Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWeb

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-22122
6.1
CVSS

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Fortinet FortiWebby Fortinet
FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4
Updated Aug 21, 2026View on NVD →
Detail

Fortinet FortiWeb is a sophisticated Web Application Firewall. It has been developed to safeguard web applications and APIs from a wide range of threats. With FortiWeb, organizations can protect their sensitive data, including financial data, customer details, and intellectual property, from web attacks and data breaches. The system has been designed to provide extensive security coverage, including threat detection, prevention, and mitigation.

The CVE-2021-22122 vulnerability was recently detected in FortiWeb GUI interface versions 6.3.0 through 6.3.7 and versions before 6.2.4. The vulnerability lies in the improper neutralization of input during web page generation and can be exploited by an unauthenticated, remote attacker. By injecting malicious payloads into various vulnerable API end-points, the attacker can perform a reflected cross-site scripting (XSS) attack.

When CVE-2021-22122 is exploited, it can lead to several consequences. By injecting malicious payloads into vulnerable API end-points, an attacker can manipulate the content displayed on the user's screen and steal sensitive information, including login credentials, session tokens, and other confidential data. This could ultimately result in the total compromise of the web application, allowing attackers to modify, delete, or access sensitive data that they should not have had access to. Consequently, web applications and APIs become vulnerable to DDoS attacks, data breaches, and other forms of cyber threats.

In conclusion, identifying and addressing vulnerabilities in digital assets is critical in protecting against cyber threats. s4e.io provides an efficient and reliable platform to learn about vulnerabilities in digital assets quickly and easily. With a powerful toolkit that allows organizations to monitor and detect vulnerabilities, they can implement effective security measures to protect their digital assets from cyber threats. Securing digital assets should not be a luxury reserved for tech giants but a necessity for all organizations that value their data.

 

REFERENCES

 

Solution Advice

To protect against CVE-2021-22122, the following precautions can be taken:

  • Update the FortiWeb GUI interface software to the latest version.
  • Implement restrictions on IP addresses and ensure that only trusted IP addresses are allowed to access vulnerable API end-points.
  • Perform regular security audits to detect vulnerabilities before they can be exploited.
  • Train employees on how to avoid falling prey to phishing emails that contain malicious payloads.
  • Use a secure password policy that mandates the use of strong passwords and ensures regular password changes.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.