An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP requests.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-280 |
![]() ![]() |
History
Tue, 14 Oct 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fortinet
Fortinet fortisiem |
|
CPEs | cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* | |
Vendors & Products |
Fortinet
Fortinet fortisiem |
Tue, 14 Oct 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP requests. | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-10-14T15:22:35.310Z
Reserved: 2025-08-28T09:14:58.078Z
Link: CVE-2025-58324

No data.

Status : Analyzed
Published: 2025-10-14T16:15:40.607
Modified: 2025-10-14T20:25:09.460
Link: CVE-2025-58324

No data.

No data.