Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-26087


An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and non-authenticated attackers in the same network as the appliance to perform a stored cross site scripting attack (XSS) via injecting malicious payloads in different locations.


Published

2025-03-17T14:15:17.247

Last Modified

2025-07-24T20:16:57.290

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiwlc ≤ 8.4.2 Yes
Application fortinet fortiwlc < 8.5.4 Yes
Application fortinet fortiwlc 8.3.3 Yes
Application fortinet fortiwlc 8.6.0 Yes

References