An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored malicious service requests
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-513 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
15 Aug 2025, 12:25
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fortinet fortisoar
Fortinet |
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-513 - Vendor Advisory | |
CPE | cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:* |
13 Aug 2025, 17:33
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
12 Aug 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-12 19:15
Updated : 2025-08-15 12:25
NVD link : CVE-2025-32932
Mitre link : CVE-2025-32932
CVE.ORG link : CVE-2025-32932
JSON object : View
Products Affected
fortinet
- fortisoar
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')