Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.
2025-02-11T17:15:21.850
2025-07-16T14:54:28.867
Analyzed
CVSSv3.1: 2.2 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisiem | ≤ 6.7.9 | Yes |
Application | fortinet | fortisiem | ≤ 7.0.3 | Yes |
Application | fortinet | fortisiem | ≤ 7.1.8 | Yes |