Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR.
2022-12-06T17:15:10.933
2024-11-21T07:16:21.520
Modified
CVSSv3.1: 3.5 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisoar | ≤ 7.0.3 | Yes |
Application | fortinet | fortisoar | 7.2.0 | Yes |