CVE-2025-22855

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages con

Severity
Low 2.6
CVSS 3.1
Exploited
Not listed
EPSS
0.004
29.7th percentile
Discovered by
Vendor
Vendor advisory field
Published
Apr 8, 2025
Assigned by fortinet

Description

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.

Weakness: CWE-79

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientEMS

Credit

Internally discovered and reported by Théo Leleu of Fortinet Product Security team. Fortinet is also pleased to thank Anders Sjögren from Root Cause Security and Yaniv Nizry from Sonar for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiClientEMS version 7.4.3 or above

Something wrong here?