CVE-2024-48893
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cros
Severity
Medium 6.4
CVSS 3.1
Exploited
Not listed
EPSS
0.005
39.4th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet
Description
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSOAR | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSOAR
Credit
Internally discovered and reported by Xin Zhao of Fortinet InfoSec team.
Vendor remediation
Please upgrade to FortiSOAR version 7.4.0 or above