CVE-2025-32932

An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all

Severity
Medium 6.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
10.7th percentile
Discovered by
Vendor
Vendor advisory field
Published
Aug 12, 2025
Assigned by fortinet

Description

An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored malicious service requests

Weakness: CWE-79

Affected products

Vendor Product Category Matched by
Fortinet FortiSOAR SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSOAR

Credit

Internally discovered and reported by Lien-Bee Huang of Fortinet Product Security team. Fortinet is also pleased to thank GAHEE LEE (이가희) from Shinhan for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiSOAR version 7.6.2 or above Please upgrade to FortiSOAR version 7.5.2 or above

Something wrong here?