FortiMail - reflected cross-site scripting vulnerability in FortiGuard URI protection


An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in FortiMail may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests to the FortiGuard URI protection service.

Affected Products

FortiMail version 7.0.1 and below
FortiMail version 6.4.5 and below
FortiMail version 6.2.7 and below


Upgrade to FortiMail version 7.0.2 or above
Upgrade to FortiMail version 6.4.6 or above
Upgrade to FortiMail version 6.2.8 or above


Fortinet is pleased to thank Braiant Giraldo Villa for reporting this vulnerability under responsible disclosure.