CVE-2025-22855
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages con
Severity
Low 2.6
CVSS 3.1
Exploited
Not listed
EPSS
0.004
29.7th percentile
Discovered by
Vendor
Vendor advisory field
Published
Apr 8, 2025
Assigned by fortinet
Description
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiClientEMS
Credit
Internally discovered and reported by Théo Leleu of Fortinet Product Security team. Fortinet is also pleased to thank Anders Sjögren from Root Cause Security and Yaniv Nizry from Sonar for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiClientEMS version 7.4.3 or above