CVE-2025-58324
⚪ Do wiadomości
Nieprawidłowe neutralizowanie danych w FortiSIEM umożliwia atak XSS przez uwierzytelnionego napastnika.
CVSS
6.4
EPSS
0.3%
Exploit
none
Vendor
fortinet
Opis źródłowy (NVD)
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP requests.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-10-14 16:15:40 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 11:10:00 UTC |
Referencje
- https://fortiguard.fortinet.com/psirt/FG-IR-24-280 ([email protected]) [Vendor Advisory]