{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-02T07:45:34.653","vulnerabilities":[{"cve":{"id":"CVE-2021-36191","sourceIdentifier":"psirt@fortinet.com","published":"2021-12-08T13:15:07.787","lastModified":"2024-11-21T06:13:17.433","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers"},{"lang":"es","value":"Una redirección de url a un sitio que no es de confianza (\"open redirect\") en Fortinet FortiWeb versión 6.4.1 y anteriores, 6.3.15 y anteriores, permite a un atacante usar el dispositivo como proxy por medio de parámetros GET diseñados en peticiones a manejadores de errores"}],"metrics":{"cvssMetricV31":[{"source":"psirt@fortinet.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0.0","versionEndIncluding":"6.0.7","matchCriteriaId":"C5931460-A0F1-4BED-ADEF-A48602EA747C"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.0","versionEndIncluding":"6.2.6","matchCriteriaId":"5F9F1235-608A-4301-904F-8CA38A153E88"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3.0","versionEndIncluding":"6.3.15","matchCriteriaId":"F59449EE-C44E-4EE7-80DC-5194A9B5B4CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiweb:6.1.0:*:*:*:*:*:*:*","matchCriteriaId":"96B929BB-7B7A-40D2-AB13-D4FDD41FD159"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiweb:6.1.1:*:*:*:*:*:*:*","matchCriteriaId":"1A3C5370-3453-4F07-B551-7E36F815578C"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiweb:6.1.2:*:*:*:*:*:*:*","matchCriteriaId":"415AF153-2A59-488B-A78B-D98B7F39B5AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*","matchCriteriaId":"74A92A08-E6F6-4522-A6DA-061950AD3525"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*","matchCriteriaId":"A6A3D2C4-C3FA-4E12-9156-DAFEA4E00BCC"}]}]}],"references":[{"url":"https://fortiguard.com/advisory/FG-IR-21-133","source":"psirt@fortinet.com","tags":["Patch","Vendor Advisory"]},{"url":"https://fortiguard.com/advisory/FG-IR-21-133","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}}]}