First published: Tue Aug 13 2024(Updated: )
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSOAR | >=6.4.0<7.3.3 | |
Fortinet FortiSOAR | =7.4.0 |
Please upgrade to FortiSOAR version 7.5.0 or above Please upgrade to FortiSOAR version 7.4.1 or above Please upgrade to FortiSOAR version 7.3.3 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.