An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] in FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiProxy 7.6.0 through 7.6.3, 7.4.0 through 7.4.9, 7.2 all versions, 7.0 all versions; FortiSASE 25.3.a may allow an unauthenticated attacker to perform a reflected cross site scripting (XSS) via crafted HTTP requests.
2025-10-14T16:15:37.423
2025-10-15T17:15:36.730
Analyzed
CVSSv3.1: 4.7 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | fortinet | fortios | < 7.4.9 | Yes |
| Operating System | fortinet | fortios | < 7.6.4 | Yes |
| Application | fortinet | fortiproxy | < 7.6.4 | Yes |
| Application | fortinet | fortisase | 25.3.40 | Yes |
| Application | fortinet | fortisase | 25.3.40 | Yes |