QID 376978

QID 376978: FortiMail - Cross-Site Scripting (XSS) Vulnerability in Webmail (FG-IR-21-045)

Fortimail provides a platform having powerful, integrated capabilities to prevent, detect, and respond to email-based threats flexible deployment options to address on-premises, cloud, and hybrid email use cases

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail Webmail may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.

Affected Versions:
FortiMail version 7.0.0 through 7.0.3
FortiMail version 6.4.0 through 6.4.7
FortiMail version 6.2.0 through 6.2.8
FortiMail version 6.0.0 through 6.0.12

QID Detection Logic(Authenticated):
QID will fire the command to get system status and will match the affected version.

Vulnerable FortiMail Webmail may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution

    Customers are advised to refer to FG-IR-21-045 for more information.

    Vendor References

    CVEs related to QID 376978

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-045 URL Logo www.fortiguard.com/psirt/FG-IR-21-045