CVE-2024-27780
Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page
Severity
Low 2.2
CVSS 3.1
Exploited
Not listed
EPSS
0.003
20.9th percentile
Discovered by
Not disclosed
Published
Feb 11, 2025
Assigned by fortinet
Description
Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSIEM | SIEM & Log Management | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiSIEM
Vendor remediation
Please upgrade to FortiSIEM version 7.3.0 or above Please upgrade to FortiSIEM version 7.2.0 or above