An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
2024-08-13T16:15:08.220
2024-08-22T14:33:54.453
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisoar | < 7.3.3 | Yes |
Application | fortinet | fortisoar | 7.4.0 | Yes |